CVE-2026-23284: net: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup()

Published Mar 25, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: mtkethsoc: Reset prog ptr to oldprog in case of error in mtkxdpsetup()

Reset eBPF program pointer to oldprog and do not decrease its ref-count if mtkopen routine in mtkxdpsetup() fails.

Affected Software

9 affected componentsFixes available
Linux Linux kernel (mtk_eth_soc ethernet driver)
Microsoft azl3 kernel 6.6.126.1-1
Linux Linux kernel>=6.0<6.1.167
Linux Linux kernel>=6.2<6.6.130
Linux Linux kernel>=6.7<6.12.77
Linux Linux kernel>=6.13<6.18.17
Linux Linux kernel>=6.19<6.19.7
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2

Event History

Mar 25, 2026
CVE Published
via MITRE·10:26 AM
Data Sourced
via MITRE·10:26 AM
Description
Data Sourced
via NVD·11:16 AM
RemedyDescriptionSeverityAffected Software
Mar 26, 2026
Data Sourced
via Microsoft·08:07 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:07 AM
DescriptionSeverity

Frequently Asked Questions

1

Which systems are realistically exposed to this issue?

Exposure is limited to systems using the Linux kernel MediaTek Ethernet SoC driver (mtk_eth_soc). The affected error path is reached when configuring an eBPF/XDP program and the driver's mtk_open routine fails.

2

What level of access is needed to exploit the vulnerability?

An attacker would need local access, high privileges, and the ability to trigger the relevant eBPF/XDP configuration failure path. The supplied CVSS vector indicates no user interaction is required, but exploitation has high attack complexity.

3

Are default configurations affected?

The provided data does not establish that a default installation is affected. It specifically involves use of the mtk_eth_soc driver together with eBPF/XDP setup and an mtk_open failure.

4

What mitigation is available before applying a fix?

If patching cannot happen immediately, reduce exposure by preventing untrusted users or workloads from obtaining the high privileges needed to configure eBPF/XDP programs, and avoid XDP program changes on interfaces using the mtk_eth_soc driver. Monitor such configuration attempts and failures on affected systems.

5

How can I determine whether a host may be affected?

Review whether the running kernel uses the mtk_eth_soc Ethernet driver and whether XDP/eBPF programs are configured or changed on its interfaces. Systems that do not use this driver are not indicated as affected by the provided information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203