๐Ÿ›ก๏ธ CVE-2026-23166
๐ŸŸก CVSS 5.5 โ€” Medium โœ… No Known Exploit CWE-476 NVD
5.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

In the Linux kernel, the following vulnerability has been resolved: ice: Fix NULL pointer dereference in ice_vsi_set_napi_queues Add NULL pointer checks in ice_vsi_set_napi_queues() to prevent crashes during resume from suspend when rings[q_idx]->q_vector is NULL. Tested adaptor: 60:00.0 Ethernet controller [0200]: Intel Corporation Ethernet Controller E810-XXV for SFP [8086:159b] (rev 02) Subsystem: Intel Corporation Ethernet Network Adapter E810-XXV-2 [8086:4003] SR-IOV state: both disabled and enabled can reproduce this issue. kernel version: v6.18 Reproduce steps: Boot up and execute suspend like systemctl suspend or rtcwake. Log: [ 231.443607] BUG: kernel NULL pointer dereference, address: 0000000000000040 [ 231.444052] #PF: supervisor read access in kernel mode [ 231.444484] #PF: error_code(0x0000) - not-present page [ 231.444913] PGD 0 P4D 0 [ 231.445342] Oops: Oops: 0000 [#1] SMP NOPTI [ 231.446635] RIP: 0010:netif_queue_set_napi+0xa/0x170 [ 231.447067] Code: 31 f6 31 ff c3 cc cc cc cc 0f 1f 80 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44 00 00 48 85 c9 74 0b 83 79 30 00 0f 84 39 01 00 00 55 41 89 d1 49 89 f8 89 f2 48 89 [ 231.447513] RSP: 0018:ffffcc780fc078c0 EFLAGS: 00010202 [ 231.447961] RAX: ffff8b848ca30400 RBX: ffff8b848caf2028 RCX: 0000000000000010 [ 231.448443] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff8b848dbd4000 [ 231.448896] RBP: ffffcc780fc078e8 R08: 0000000000000000 R09: 0000000000000000 [ 231.449345] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000001 [ 231.449817] R13: ffff8b848dbd4000 R14: ffff8b84833390c8 R15: 0000000000000000 [ 231.450265] FS: 00007c7b29e9d740(0000) GS:ffff8b8c068e2000(0000) knlGS:0000000000000000 [ 231.450715] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 231.451179] CR2: 0000000000000040 CR3: 000000030626f004 CR4: 0000000000f72ef0 [ 231.451629] PKRU: 55555554 [ 231.452076] Call Trace: [ 231.452549] [ 231.452996] ? ice_vsi_set_napi_queues+0x4d/0x110 [ice] [ 231.453482] ice_resume+0xfd/0x220 [ice] [ 231.453977] ? __pfx_pci_pm_resume+0x10/0x10 [ 231.454425] pci_pm_resume+0x8c/0x140 [ 231.454872] ? __pfx_pci_pm_resume+0x10/0x10 [ 231.455347] dpm_run_callback+0x5f/0x160 [ 231.455796] ? dpm_wait_for_superior+0x107/0x170 [ 231.456244] device_resume+0x177/0x270 [ 231.456708] dpm_resume+0x209/0x2f0 [ 231.457151] dpm_resume_end+0x15/0x30 [ 231.457596] suspend_devices_and_enter+0x1da/0x2b0 [ 231.458054] enter_state+0x10e/0x570 Add defensive checks for both the ring pointer and its q_vector before dereferencing, allowing the system to resume successfully even when q_vectors are unmapped.

Details

Severity MEDIUM
CVSS Score 5.5
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE CWE-476
Public Exploit โœ… No
Source NVD
Published 2026-02-14
Updated 2026-06-02
Modified 2026-03-18

Affected Packages

Software From version Fixed in
linux-kernel โ€” โ€”

Similar Threats

Free Vulnerability Check

Is your WordPress site affected?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against known CVE records.

Scan My Site Free โ†’

No credit card required  ยท  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.