{"id":"CVE-2026-23422","title":"dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler\n\nCommit 31a7a0bbeb00 (\"dpaa2-switch: add bounds check for if_id in IRQ\nhandler\") introduces a…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 77611cab5bdfff7a070ae574bbfba20a1de99d1b < 7def51cb9fb8b8d5342443372b8cf28d8fbd7f3d","Linux >= 34b56c16efd61325d80bf1d780d0e176be662f59 < b5bababe7703a7322bc59b803ab1587887a2a5e4","Linux >= f89e33c9c37f0001b730e23b3b05ab7b1ecface2 < c7becfe3e604d138bd53b8ac3111b2b3e8ec6b0e","Linux >= 2447edc367800ba914acf7ddd5d250416b45fb31 < fa4412cdc5178a48799bafcb8af28fd2fbf3d703","Linux >= 1b381a638e1851d8cfdfe08ed9cdbec5295b18c9 < 00f42ace446f1e4bf84988f2281131f52cd32796","Linux >= 31a7a0bbeb006bac2d9c81a2874825025214b6d8 < 28fd8ac1d49389cb230d712116f54e27ebec11b8","Linux >= 31a7a0bbeb006bac2d9c81a2874825025214b6d8 < 74badb9c20b1a9c02a95c735c6d3cd6121679c93","Linux >= 5.15.200 < 5.15.203","Linux >= 6.1.163 < 6.1.167","Linux >= 6.6.124 < 6.6.130","Linux >= 6.12.70 < 6.12.77","Linux >= 6.18.10 < 6.18.17","Linux 6.19"],"published":"2026-04-03","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:46:03.923Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-23422","references":[{"url":"https://git.kernel.org/stable/c/7def51cb9fb8b8d5342443372b8cf28d8fbd7f3d"},{"url":"https://git.kernel.org/stable/c/b5bababe7703a7322bc59b803ab1587887a2a5e4"},{"url":"https://git.kernel.org/stable/c/c7becfe3e604d138bd53b8ac3111b2b3e8ec6b0e"},{"url":"https://git.kernel.org/stable/c/fa4412cdc5178a48799bafcb8af28fd2fbf3d703"},{"url":"https://git.kernel.org/stable/c/00f42ace446f1e4bf84988f2281131f52cd32796"},{"url":"https://git.kernel.org/stable/c/28fd8ac1d49389cb230d712116f54e27ebec11b8"},{"url":"https://git.kernel.org/stable/c/74badb9c20b1a9c02a95c735c6d3cd6121679c93"}],"tags":["cve.org"],"epss":0.00123,"epssPercentile":0.01771,"ingestedAt":"2026-09-08T15:33:26.992Z","slug":"CVE-2026-23422","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler\n\nCommit 31a7a0bbeb00 (\"dpaa2-switch: add bounds check for if_id in IRQ\nhandler\") introduces a range check for if_id to avoid an out-of-bounds\naccess. If an out-of-bounds if_id is detected, the interrupt status is\nnot cleared. This may result in an interrupt storm.\n\nClear the interrupt status after detecting an out-of-bounds if_id to avoid\nthe problem.\n\nFound by an experimental AI code review agent at Google.\n\n## Affected\n\n- `Linux >= 77611cab5bdfff7a070ae574bbfba20a1de99d1b < 7def51cb9fb8b8d5342443372b8cf28d8fbd7f3d`\n- `Linux >= 34b56c16efd61325d80bf1d780d0e176be662f59 < b5bababe7703a7322bc59b803ab1587887a2a5e4`\n- `Linux >= f89e33c9c37f0001b730e23b3b05ab7b1ecface2 < c7becfe3e604d138bd53b8ac3111b2b3e8ec6b0e`\n- `Linux >= 2447edc367800ba914acf7ddd5d250416b45fb31 < fa4412cdc5178a48799bafcb8af28fd2fbf3d703`\n- `Linux >= 1b381a638e1851d8cfdfe08ed9cdbec5295b18c9 < 00f42ace446f1e4bf84988f2281131f52cd32796`\n- `Linux >= 31a7a0bbeb006bac2d9c81a2874825025214b6d8 < 28fd8ac1d49389cb230d712116f54e27ebec11b8`\n- `Linux >= 31a7a0bbeb006bac2d9c81a2874825025214b6d8 < 74badb9c20b1a9c02a95c735c6d3cd6121679c93`\n- `Linux >= 5.15.200 < 5.15.203`\n- `Linux >= 6.1.163 < 6.1.167`\n- `Linux >= 6.6.124 < 6.6.130`\n- `Linux >= 6.12.70 < 6.12.77`\n- `Linux >= 6.18.10 < 6.18.17`\n- `Linux 6.19`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}