Review reviewHigh

CVE-2023-54129

Linux

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Add validation for lmac type Upon physical link change, firmware reports to the kernel about the change along with the details like speed, lmac_type_id, etc. Kernel derives lmac_type based on lmac_type_id received from firmware. In a few scenarios, firmware returns an invalid lmac_type_id, which is resulting in below kernel panic. This patch adds the missing validation of the lmac_type_id field. Internal error: Oops: 96000005 [#1] PREEMPT SMP [ 35.321595] Modules linked in: [ 35.328982] CPU: 0 PID: 31 Comm: kw...

CVSS
7.1
EPSS
0.27%
18.8% percentile
CISA KEV
Not listed
Published
2025.12.24
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.27%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Add validation for lmac type Upon physical link change, firmware reports to the kernel about the change along with the details like speed, lmac_type_id, etc. Kernel derives lmac_type based on lmac_type_id received from firmware. In a few scenarios, firmware returns an invalid lmac_type_id, which is resulting in below kernel panic. This patch adds the missing validation of the lmac_type_id field. Internal error: Oops: 96000005 [#1] PREEMPT SMP [ 35.321595] Modules linked in: [ 35.328982] CPU: 0 PID: 31 Comm: kw...

Affected product and versions

Product
Linux
Affected versions
>= 61071a871ea6eb2125ece91c1a0dbb124a318c8a < 4392454c694b13d78c84165c0964729772cd3b73, >= 61071a871ea6eb2125ece91c1a0dbb124a318c8a < 83a7f27c5b94e43f29f8216a32790751139aa61e, >= 61071a871ea6eb2125ece91c1a0dbb124a318c8a < afd7660c766c4d317feae004e5cd829390bbc4b0, >= 61071a871ea6eb2125ece91c1a0dbb124a318c8a < 5c0268b141ad612b6fca13d3a66cfda111716dbb, >= 61071a871ea6eb2125ece91c1a0dbb124a318c8a < cb5edce271764524b88b1a6866b3e626686d9a33, >= 4.20
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CWE
Not available