CVE-2026-74317: ixgbe: do not configure xps for XDP queues

Published Aug 15, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ixgbe: do not configure xps for XDP queues

netifsetxpsqueue() should not be called for an XDP Tx queue, since such queues are not netdev-exposed. On systems with number of CPUs >=64, on E610 adapter, netdev is configured with maximum number queue pairs being 63 (due to MSI-X assignment), but configuring XDP results in 64 XDP queues.

So, during XDP program load, when netifsetxpsqueue() is called for the last XDP queue, we get a WARNING with a call trace and KASAN report afterwards (if enabled).

[ 2012.699800] WARNING: net/core/dev.c:2854 at netifsetxpsqueue+0x116a/0x1e40, CPU#36: xdpsock/103668 [...] [ 2012.700029] RIP: 0010:netifsetxpsqueue+0x116a/0x1e40 [ 2012.700035] Code: b6 34 06 48 89 f8 83 e0 07 83 c0 01 40 38 f0 7c 09 40 84 f6 0f 85 03 0a 00 00 0f b7 44 24 40 66 43 89 44 6a 18 e9 01 fb ff ff <0f> 0b e9 f2 ee ff ff 44 8b 44 24 44 45 85 c0 74 50 4d 85 e4 0f 84 [ 2012.700040] RSP: 0018:ffff8882369aeb28 EFLAGS: 00010246 [ 2012.700046] RAX: 0000000000000000 RBX: 000000000000003f RCX: 0000000000000000 [ 2012.700050] RDX: 1ffff1111da3d891 RSI: ffff888120e34250 RDI: ffff8888ed1ec488 [ 2012.700054] RBP: ffff888913281560 R08: 0000000000000000 R09: ffff8888ed1ec000 [ 2012.700058] R10: ffff8888a2e83180 R11: 0000000000000000 R12: 0000000000007fa8 [ 2012.700061] R13: 000000000000003f R14: ffff888120e34854 R15: ffff8889132817c8 [ 2012.700065] FS: 00007fc8ea9ff740(0000) GS:ffff88884cefe000(0000) knlGS:0000000000000000 [ 2012.700069] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 2012.700073] CR2: 00007f81c8000020 CR3: 00000002299f8006 CR4: 00000000007726f0 [ 2012.700077] PKRU: 55555554 [ 2012.700080] Call Trace: [ 2012.700084] <TASK> [ 2012.700087] ? ktimeget+0x61/0x150 [ 2012.700097] ? usleeprangestate+0x133/0x1b0 [ 2012.700108] ? pfxusleeprangestate+0x10/0x10 [ 2012.700114] netifsetxpsqueue+0x31/0x50 [ 2012.700119] ixgbeconfiguretxring+0x472/0x920 [ixgbe] [...] [ 2012.700486] ixgbexdp+0x38f/0x750 [ixgbe]

[...]

[ 2012.701094] BUG: KASAN: slab-out-of-bounds in netifsetxpsqueue+0x1ac5/0x1e40 [ 2012.701100] Write of size 4 at addr ffff88888d43cff8 by task xdpsock/103668

Skip XPS configuration for XDP Tx queues.

Affected Software

1 affected component
Intel ixgbe (Linux kernel driver)

Event History

Aug 15, 2026
CVE Published
via MITRE·05:58 AM
Data Sourced
via MITRE·05:58 AM
DescriptionSeverity
Data Sourced
via NVD·06:22 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2026-74317?

CVE-2026-74317 has a risk score of 23.

2

How do I fix CVE-2026-74317?

To fix CVE-2026-74317, update the Intel ixgbe driver in your Linux kernel to a version that contains the patch.

3

What systems are affected by CVE-2026-74317?

CVE-2026-74317 affects systems using the Intel ixgbe driver on configurations with 64 or more CPUs.

4

What does CVE-2026-74317 impact?

CVE-2026-74317 impacts the configuration of XDP Tx queues in the Linux kernel.

5

Who is responsible for resolving CVE-2026-74317?

The resolution of CVE-2026-74317 falls under the maintenance and updates of the Linux kernel and its associated drivers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203