« Volver al listado

CVE-2026-80998

Estado: RecibidaAlta (7.5)—

In the Linux kernel, the following vulnerability has been resolved:

net: bnxt: ring the doorbell when SW USO exits early

When a burst of packets is handed down to the driver, the driver defers the doorbell to the end by setting txr->kick_pending = 1. The normal TX path handles this, but the SW USO path can miss it if it returns early.

If bnxt_sw_udp_gso_xmit runs but returns early with NETDEV_TX_BUSY and txr->kick_pending was previously set to 1, then the TX queue can stall because the driver wrote some BDs but never wrote the doorbell. The device won't know to do the TX which would generate the completion that would wake the queue back up.

Leer descripción completaMostrar menos

Simplify bnxt_sw_udp_gso_xmit to set txr->kick_pending in its success case and check the flag on return. The added check after bnxt_sw_udp_gso_xmit returns ensures that any pending doorbells are written handling both successful USO and any early returns, which prevents the TX queue stall mentioned above.

This TX queue stall was observed on a production system with a netdev TX watchdog informing about the queue stall.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80998",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "cc5d90667db81474ed7a92a1b2fa3daec5559307",
              "lessThan": "48d1c9665db6e3d4aeca62eb669377162ebc6fdf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cc5d90667db81474ed7a92a1b2fa3daec5559307",
              "lessThan": "4e15e89faac9f308baeb01f46c13a051814d2449",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/broadcom/bnxt/bnxt.c",
            "drivers/net/ethernet/broadcom/bnxt/bnxt_gso.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/broadcom/bnxt/bnxt.c",
            "drivers/net/ethernet/broadcom/bnxt/bnxt_gso.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:06.873",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/48d1c9665db6e3d4aeca62eb669377162ebc6fdf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4e15e89faac9f308baeb01f46c13a051814d2449",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bnxt: ring the doorbell when SW USO exits early\n\nWhen a burst of packets is handed down to the driver, the driver defers\nthe doorbell to the end by setting txr->kick_pending = 1. The normal TX\npath handles this, but the SW USO path can miss it if it returns\nearly.\n\nIf bnxt_sw_udp_gso_xmit runs but returns early with NETDEV_TX_BUSY and\ntxr->kick_pending was previously set to 1, then the TX queue can\nstall because the driver wrote some BDs but never wrote the doorbell.\nThe device won't know to do the TX which would generate the completion\nthat would wake the queue back up.\n\nSimplify bnxt_sw_udp_gso_xmit to set txr->kick_pending in its success\ncase and check the flag on return. The added check after\nbnxt_sw_udp_gso_xmit returns ensures that any pending doorbells are\nwritten handling both successful USO and any early returns, which\nprevents the TX queue stall mentioned above.\n\nThis TX queue stall was observed on a production system with a netdev TX\nwatchdog informing about the queue stall."
    }
  ],
  "lastModified": "2026-09-13T07:17:06.483",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}