CVE-2026-23422: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler Commit 31a7a0bbeb00 ("dpaa2-switch: add bounds check for if_id in IRQ handler") introduces a range check for if_id to avoid an out-of-bounds access. If an out-of-bounds if_id is detected, the interrupt status is not cleared. This may result in an interrupt storm. Clear the interrupt status after detecting an out-of-bounds if_id to avoid the problem. Found by an experimental AI code review agent at Google.
Affected products
- Linux Linux Kernel: from 5.15.200, before 5.15.203 (fixed in 5.15.203); from 6.1.163, before 6.1.167 (fixed in 6.1.167); from 6.6.124, before 6.6.130 (fixed in 6.6.130); from 6.12.70, before 6.12.77 (fixed in 6.12.77); from 6.18.10, before 6.18.17 (fixed in 6.18.17); from 6.19.1, before 6.19.7 (fixed in 6.19.7); …
Published 2026-04-03. Last modified 2026-07-24.