« Volver al listado

CVE-2026-97573

Estado: RecibidaAlta (8.1)—

In the Linux kernel, the following vulnerability has been resolved:

bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()

bnxt_rx_ring_reset() frees the ring buffers and then reallocates them, ignoring the result.

bnxt_alloc_one_rx_ring() can fail in bnxt_alloc_one_tpa_info_data(), which returns -ENOMEM on the first failed allocation and leaves the remaining rxr->rx_tpa[] entries zeroed.

The error isn't propagated up, so the loop in bnxt_rx_ring_reset continues and at the end the code re-enables TPA with partially unallocated rx_tpa array.

This means that when the agg_id from hardware is mapped to a SW index in rxr->rx_tpa[], an uninitialized slot can be chosen which would hand a zero DMA address to the device.

Leer descripción completaMostrar menos

Fix this by falling back to a global reset, which is what the existing code already does when other functions fail, but unlike the other failure cases this particular failure has to return because TPA can't be re-enabled since the allocation failed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad en controlador de red Linux (bnxt_en) explotable remotamente (AV:N) mediante fallo de asignación de memoria no manejado que causa corrupción de datos o DoS al mapear índices de DMA con direcciones nulas.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97573",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8fbf58e17dce8f250dda9ad6b0a49b3041f0af14",
              "lessThan": "52fc97cbc3ba118aad84e7c001bf02ebe8496f70",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8fbf58e17dce8f250dda9ad6b0a49b3041f0af14",
              "lessThan": "40b4a7bb6b0b872b45f017dbf211268de098b75c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8fbf58e17dce8f250dda9ad6b0a49b3041f0af14",
              "lessThan": "af9a2bdaba0b4ceb0fc5e5122ef3fc6b7e5a366a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8fbf58e17dce8f250dda9ad6b0a49b3041f0af14",
              "lessThan": "cfec9e7f15a56cb0104bac13d01e5d11e1ba84fb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8fbf58e17dce8f250dda9ad6b0a49b3041f0af14",
              "lessThan": "1a3670b6a6b5679fe56c5890157b344f091e64f8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8fbf58e17dce8f250dda9ad6b0a49b3041f0af14",
              "lessThan": "4a17c73c83798c2fa9c7920ad5a98803adce3e01",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8fbf58e17dce8f250dda9ad6b0a49b3041f0af14",
              "lessThan": "8b2fd5c0aeda935294159206af9d6179282d425a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8fbf58e17dce8f250dda9ad6b0a49b3041f0af14",
              "lessThan": "961e2a17c5e3559b3f8654d2daabdd25a42e770a",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:08.017",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1a3670b6a6b5679fe56c5890157b344f091e64f8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/40b4a7bb6b0b872b45f017dbf211268de098b75c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4a17c73c83798c2fa9c7920ad5a98803adce3e01",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/52fc97cbc3ba118aad84e7c001bf02ebe8496f70",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8b2fd5c0aeda935294159206af9d6179282d425a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/961e2a17c5e3559b3f8654d2daabdd25a42e770a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/af9a2bdaba0b4ceb0fc5e5122ef3fc6b7e5a366a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cfec9e7f15a56cb0104bac13d01e5d11e1ba84fb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()\n\nbnxt_rx_ring_reset() frees the ring buffers and then reallocates them,\nignoring the result.\n\nbnxt_alloc_one_rx_ring() can fail in bnxt_alloc_one_tpa_info_data(), which\nreturns -ENOMEM on the first failed allocation and leaves the remaining\nrxr->rx_tpa[] entries zeroed.\n\nThe error isn't propagated up, so the loop in bnxt_rx_ring_reset\ncontinues and at the end the code re-enables TPA with partially\nunallocated rx_tpa array.\n\nThis means that when the agg_id from hardware is mapped to a SW index in\nrxr->rx_tpa[], an uninitialized slot can be chosen which would hand a\nzero DMA address to the device.\n\nFix this by falling back to a global reset, which is what the existing\ncode already does when other functions fail, but unlike the other\nfailure cases this particular failure has to return because TPA can't\nbe re-enabled since the allocation failed."
    }
  ],
  "lastModified": "2026-10-03T11:18:04.533",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}