← All Advisories

CVE-2026-97435

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97435

Key Details

CVECVE-2026-97435
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: dsa: sja1105: flower: reject cross-chip redirect

dsa_port_from_netdev() may return a valid port from a different switch

chip. Programming another chip's port index into the local hardware

causes redirection to the wrong port, or an out-of-bounds access if the

index exceeds the local chip's port count.

Apply a minimal fix that adds a check to catch this case and adjusts the

extack message. When cls->common.skip_sw is not set, the operation could

instead redirect to the upstream port and let the software or upstream

switch(es) handle the forward, but that is not addressed here. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97435
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97435