---
id: CVE-2026-23054
title: 'net: hv_netvsc: reject RSS hash key programming without RX indirection table'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: hv_netvsc: reject RSS hash key programming without RX indirection table

  RSS configuration requires a valid RX indirection table. When the device
  reports a single …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 <
    8288136f508e78eb3563e7073975999cf225a2f9
  - >-
    Linux >= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 <
    82c9039c8ebb715753a40434df714f865a3aec9c
  - >-
    Linux >= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 <
    4cd55c609e85ae2313248ef1a33619a3eef44a16
  - >-
    Linux >= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 <
    11dd9a9ef4dc4507a15a69b8511a0013c6c28fa3
  - >-
    Linux >= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 <
    d23564955811da493f34412d7de60fa268c8cb50
  - Linux 4.11
published: '2026-02-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:44:43.726Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-23054'
references:
  - url: 'https://git.kernel.org/stable/c/8288136f508e78eb3563e7073975999cf225a2f9'
  - url: 'https://git.kernel.org/stable/c/82c9039c8ebb715753a40434df714f865a3aec9c'
  - url: 'https://git.kernel.org/stable/c/4cd55c609e85ae2313248ef1a33619a3eef44a16'
  - url: 'https://git.kernel.org/stable/c/11dd9a9ef4dc4507a15a69b8511a0013c6c28fa3'
  - url: 'https://git.kernel.org/stable/c/d23564955811da493f34412d7de60fa268c8cb50'
tags:
  - cve.org
epss: 0.00184
epssPercentile: 0.07094
ingestedAt: '2026-09-08T15:33:26.994Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: hv_netvsc: reject RSS hash key programming without RX indirection table

RSS configuration requires a valid RX indirection table. When the device
reports a single receive queue, rndis_filter_device_add() does not
allocate an indirection table, accepting RSS hash key updates in this
state leads to a hang.

Fix this by gating netvsc_set_rxfh() on ndc->rx_table_sz and return
-EOPNOTSUPP when the table is absent. This aligns set_rxfh with the device
capabilities and prevents incorrect behavior.

## Affected

- `Linux >= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 < 8288136f508e78eb3563e7073975999cf225a2f9`
- `Linux >= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 < 82c9039c8ebb715753a40434df714f865a3aec9c`
- `Linux >= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 < 4cd55c609e85ae2313248ef1a33619a3eef44a16`
- `Linux >= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 < 11dd9a9ef4dc4507a15a69b8511a0013c6c28fa3`
- `Linux >= 962f3fee83a4ef9010ae84dc43ae7aecb572e2a9 < d23564955811da493f34412d7de60fa268c8cb50`
- `Linux 4.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
