CVE-2026-97574
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Don't free the live ring's TPA state on queue restart failure
bnxt_queue_mem_alloc() shallow copies the live RX ring into the clone:
the code currently clears pointers that the clone owns (such as rx_agg_bmap), but rx_tpa and rx_tpa_idx_map are left pointing at memory of the live ring that was cloned.
If an allocation failure happens later and the err_free_tpa_info label is taken, the live ring's memory can be freed while still in use.
Fix this by initializing the clone's pointers to NULL to prevent live ring state from being freed inadvertently.
Detalles técnicos trazas, registros y código del informe original
memcpy(clone, rxr, sizeof(*rxr));
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97574",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "0997443906b96a051011f220a61e6dce4602ec54",
"lessThan": "e42287b4d38d653f7d4a47f6c29b0c01288bb050",
"versionType": "git"
},
{
"status": "affected",
"version": "bd649c5cc958169b8a8a3e77ea926d92d472b02a",
"lessThan": "8ade95619cbfd1fc57f0f1a9a5ebdca2345a8d27",
"versionType": "git"
},
{
"status": "affected",
"version": "bd649c5cc958169b8a8a3e77ea926d92d472b02a",
"lessThan": "0596a7caa6fc283e142716739099c038d8714082",
"versionType": "git"
},
{
"status": "affected",
"version": "bd649c5cc958169b8a8a3e77ea926d92d472b02a",
"lessThan": "5ce7f36c334d723954855ac769ede2fe0e8f89c8",
"versionType": "git"
},
{
"status": "affected",
"version": "6.12.20",
"lessThan": "6.12.112",
"versionType": "semver"
}
],
"programFiles": [
"drivers/net/ethernet/broadcom/bnxt/bnxt.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/broadcom/bnxt/bnxt.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:08.127",
"references": [
{
"url": "https://git.kernel.org/stable/c/0596a7caa6fc283e142716739099c038d8714082",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5ce7f36c334d723954855ac769ede2fe0e8f89c8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8ade95619cbfd1fc57f0f1a9a5ebdca2345a8d27",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e42287b4d38d653f7d4a47f6c29b0c01288bb050",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Don't free the live ring's TPA state on queue restart failure\n\nbnxt_queue_mem_alloc() shallow copies the live RX ring into the clone:\n\n memcpy(clone, rxr, sizeof(*rxr));\n\nthe code currently clears pointers that the clone owns (such as\nrx_agg_bmap), but rx_tpa and rx_tpa_idx_map are left pointing at memory\nof the live ring that was cloned.\n\nIf an allocation failure happens later and the err_free_tpa_info label\nis taken, the live ring's memory can be freed while still in use.\n\nFix this by initializing the clone's pointers to NULL to prevent live\nring state from being freed inadvertently."
}
],
"lastModified": "2026-10-03T11:18:04.677",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}