net: hv_netvsc: reject RSS hash key programming without RX indirection table
In the Linux kernel, the following vulnerability has been resolved: net: hv_netvsc: reject RSS hash key programming without RX indirection table RSS configuration requires a valid RX indirection table. When the device reports a single receive queue, rndis_filter_device_add() does not allocate an indirection table, accepting RSS hash key updates in this state leads to a hang. Fix this by gating netvsc_set_rxfh() on ndc->rx_table_sz and return -EOPNOTSUPP when the table is absent. This aligns set_rxfh with the device capabilities and prevents incorrect behavior.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
In the Linux kernel, the following vulnerability has been resolved: net: hv_netvsc: reject RSS hash key programming without RX indirection table RSS configuration requires a valid RX indirection table. When the device reports a single receive queue, rndis_filter_device_add() does not allocate an indirection table, accepting RSS hash key updates in this state leads to a hang. Fix this by gating netvsc_set_rxfh() on ndc->rx_table_sz and return -EOPNOTSUPP when the table is absent. This aligns set_rxfh with the device capabilities and prevents incorrect behavior.
05 / REFERENCES
Further evidence
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
- https://git.kernel.org/stable/c/11dd9a9ef4dc4507a15a69b8511a0013c6c28fa3
- https://git.kernel.org/stable/c/4cd55c609e85ae2313248ef1a33619a3eef44a16
- https://git.kernel.org/stable/c/8288136f508e78eb3563e7073975999cf225a2f9
- https://git.kernel.org/stable/c/82c9039c8ebb715753a40434df714f865a3aec9c
- https://git.kernel.org/stable/c/d23564955811da493f34412d7de60fa268c8cb50
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23054.json
- https://nvd.nist.gov/vuln/detail/CVE-2026-23054