---
cve: "CVE-2026-23422"
severity: "LOW"
cvss: 3.1
epss: "12%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-04-03 14:16:28"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T05:10:55+02:00"
---

# CVE-2026-23422

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler

Commit 31a7a0bbeb00 ("dpaa2-switch: add bounds check for if_id in IRQ
handler") introduces a range check for if_id to avoid an out-of-bounds
access. If an out-of-bounds if_id is detected, the interrupt status is
not cleared. This may result in an interrupt storm.

Clear the interrupt status after detecting an out-of-bounds if_id to avoid
the problem.

Found by an experimental AI code review agent at Google.

## Patch verfügbar (OSV)

- Kernel ≥ 5.15.203
- Kernel ≥ 6.1.167
- Kernel ≥ 6.6.130
- Kernel ≥ 6.12.77
- Kernel ≥ 6.18.17
- Kernel ≥ 6.19.7

## Referenzen

- <https://git.kernel.org/stable/c/7def51cb9fb8b8d5342443372b8cf28d8fbd7f3d>
- <https://git.kernel.org/stable/c/b5bababe7703a7322bc59b803ab1587887a2a5e4>
- <https://git.kernel.org/stable/c/c7becfe3e604d138bd53b8ac3111b2b3e8ec6b0e>
- <https://git.kernel.org/stable/c/fa4412cdc5178a48799bafcb8af28fd2fbf3d703>
- <https://git.kernel.org/stable/c/00f42ace446f1e4bf84988f2281131f52cd32796>
- <https://git.kernel.org/stable/c/28fd8ac1d49389cb230d712116f54e27ebec11b8>
- <https://git.kernel.org/stable/c/74badb9c20b1a9c02a95c735c6d3cd6121679c93>
- <https://cert-portal.siemens.com/productcert/html/ssa-019113.html>
- <https://cert-portal.siemens.com/productcert/html/ssa-082556.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-23422) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
