CVE-2026-74697
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
EOP (End of frame padding) on the AGG ring may cause overlapping of zero padding at the end of one segment with the next segment's data. If Relaxed Ordering (RO) is enabled, the zero padding may overwrite valid data in the next segment and corrupt the data. Older chips (P5 and older) do not automatically disable RO when EOP is enabled. On some ARM systems, data corruption was reported on 57508 (P5) chips with RO enabled.
Always disable EOP on all chips on the AGG rings when TPA is enabled to fix the data corruption.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
- Puntuación base: 8.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.61%
- Percentil entre todas las CVEs puntuadas: 47
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access60 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/410da4428b1f47bf9a84bdc0bcaa089d73ba2048
- https://git.kernel.org/stable/c/68c181af7cd1ca9cbf29acd95911073bfd3c6397
- https://git.kernel.org/stable/c/7aee22a35978b44784612c156e358e375ddf5d16
- https://git.kernel.org/stable/c/aab3b5f4d8ec8598606ee011e219ef824ae25ca0
- https://git.kernel.org/stable/c/b61c4911204a0a2f900e538d64ceb608f6c9614d
- https://git.kernel.org/stable/c/c1962ab4645a914a91ff492735881150ddc8a79e
- https://git.kernel.org/stable/c/c3faf548a00f4c17100cc9204746975fa46a73b9
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74697",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 4.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"lessThan": "68c181af7cd1ca9cbf29acd95911073bfd3c6397",
"versionType": "git"
},
{
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"lessThan": "7aee22a35978b44784612c156e358e375ddf5d16",
"versionType": "git"
},
{
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"lessThan": "410da4428b1f47bf9a84bdc0bcaa089d73ba2048",
"versionType": "git"
},
{
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"lessThan": "b61c4911204a0a2f900e538d64ceb608f6c9614d",
"versionType": "git"
},
{
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"lessThan": "aab3b5f4d8ec8598606ee011e219ef824ae25ca0",
"versionType": "git"
},
{
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"lessThan": "c1962ab4645a914a91ff492735881150ddc8a79e",
"versionType": "git"
},
{
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"lessThan": "c3faf548a00f4c17100cc9204746975fa46a73b9",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/ethernet/broadcom/bnxt/bnxt.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.4",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/broadcom/bnxt/bnxt.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-22T16:16:44.280",
"references": [
{
"url": "https://git.kernel.org/stable/c/410da4428b1f47bf9a84bdc0bcaa089d73ba2048",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/68c181af7cd1ca9cbf29acd95911073bfd3c6397",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7aee22a35978b44784612c156e358e375ddf5d16",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/aab3b5f4d8ec8598606ee011e219ef824ae25ca0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b61c4911204a0a2f900e538d64ceb608f6c9614d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c1962ab4645a914a91ff492735881150ddc8a79e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c3faf548a00f4c17100cc9204746975fa46a73b9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Disable EOP for TPA on all chips to prevent data corruption\n\nEOP (End of frame padding) on the AGG ring may cause overlapping of\nzero padding at the end of one segment with the next segment's data.\nIf Relaxed Ordering (RO) is enabled, the zero padding may overwrite\nvalid data in the next segment and corrupt the data. Older chips\n(P5 and older) do not automatically disable RO when EOP is enabled.\nOn some ARM systems, data corruption was reported on 57508 (P5)\nchips with RO enabled.\n\nAlways disable EOP on all chips on the AGG rings when TPA is enabled\nto fix the data corruption."
}
],
"lastModified": "2026-08-25T06:18:53.313",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}