CVE-2026-23165: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: sfc: fix deadlock in RSS config read Since cited commit, core locks the net_device's rss_lock when handling ethtool -x command, so driver's implementation should not lock it again. Remove the latter.
Affected products
- Linux Linux Kernel: from 6.17, before 6.18.9 (fixed in 6.18.9); version 6.19 only
Published 2026-02-14. Last modified 2026-06-17.