CVE-2026-43094 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ixgbevf: add missing negotiate_features op to Hyper-V ops table Commit a7075f501bd3 ("ixgbevf: fix mailbox API compatibility by negotiating supported features") added the .negotiate_features callback to ixgbe_mac_operations and populated it in ixgbevf_mac_ops, but forgot to add it to ixgbevf_hv_mac_ops. This leaves the function pointer NULL on Hyper-V VMs. During probe, ixgbevf_negotiate_api() calls ixgbevf_set_features(), which unconditionally dereferences hw->mac.ops.negotiate_features(). On Hyper-V this results in a NULL pointer dereference: BUG: kernel NULL pointer dereference, address: 0000000000000000 [...] Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine [...] Workqueue: events work_for_cpu_fn RIP: 0010:0x0 [...] Call Trace: ixgbevf_negotiate_api+0x66/0x160 [ixgbevf] ixgbevf_sw_init+0xe4/0x1f0 [ixgbevf] ixgbevf_probe+0x20f/0x4a0 [ixgbevf] local_pci_probe+0x50/0xa0 work_for_cpu_fn+0x1a/0x30 [...] Add ixgbevf_hv_negotiate_features_vf() that returns -EOPNOTSUPP and wire it into ixgbevf_hv_mac_ops. The caller already handles -EOPNOTSUPP gracefully.
A vulnerability in the Linux kernel's ixgbevf driver for Intel Ethernet Virtual Function (VF) can lead to a NULL pointer dereference on Hyper-V virtual machines. This issue arises because the .negotiate_features callback was not properly assigned in the Hyper-V operations table, leaving the function pointer NULL. When the driver is probed, it attempts to call the negotiate_features function, which results in a kernel NULL pointer dereference. This vulnerability affects the Linux kernel ixgbevf driver on Hyper-V VMs.
The vulnerability has been addressed in the Linux kernel. Users can upgrade to the latest version of the stable Linux kernel to apply the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/1455ff8809843e6e83f1f5b5c0bcc2224c99a3cb | kernel.org | Patch |
| https://git.kernel.org/stable/c/2270ebab53128fb73c4a70a292be09094074737f | kernel.org | Patch |
| https://git.kernel.org/stable/c/376d74ea03589914fbe2dedcbebf418396c04fd0 | kernel.org | |
| https://git.kernel.org/stable/c/4821d563cd7f251ae728be1a6d04af82a294a5b9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4db7b61ec1d1b2b67c0881b62fc4f9583bc21484 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d8a747057a17ffc79e31df1abb11d05e1669d8e5 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.1.158, < 6.2 >= 6.6.114, < 6.6.136 >= 6.12.55, < 6.12.83 >= 6.17.5, < 6.18 >= 6.18.1, < 6.18.24 >= 6.19, < 6.19.14 6.18 - 6.18 rc2 6.18 rc3 6.18 rc4 6.18 rc5 6.18 rc6 6.18 rc7 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 7.0 rc7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 19, 2026 | Initial Analysis | [email protected] |
| May 6, 2026 | New CVE Received | kernel.org |