s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2026-97570

📛 CVE Title

bnxt_en: Bound SW TPA IDs to prevent crashes

Description

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Bound SW TPA IDs to prevent crashes FW supports up to 1024 concurrent TPAs, so the FW TPA ID is in the range 0..1023 (see commit ec4d8e7cf024 ("bnxt_en: Add TPA ID mapping logic for 57500 chips.")). bnxt_alloc_agg_idx is intended to wrap the FW ID down to a software ID which is used to index rxr->rx_tpa, and to generate a mapping between FW IDs and the wrapped software ID. On a 57608 with firmware version 233, the firmware advertises 32 concurrent TPAs. As of the commit under fixes, bp->max_tpa on this NIC is set to 32. If the software ID from bnxt_alloc_agg_idx is above 31, this results in an invalid address being loaded on this line: tpa_info = &rxr->rx_tpa[agg_id]; because rx_tpa is allocated with only bp->max_tpa (32) entries. Writes to tpa_info later in the code are out of bounds. This bug results in a crash at boot: Oops: general protection fault, kernel NULL pointer dereference 0x8: 0000 [#1] SMP NOPTI RIP: 0010:bnxt_rx_pkt+0xc0/0x1560 RSP: 0018:ffffc900009b8c78 EFLAGS: 00010246 RAX: 0000000000000000 RBX: 0000000000000048 RCX: 0000000206682516 RDX: ffffc900009b8db4 RSI: 0000000000000000 RDI: 01ffffff038fe1c0 RBP: ffffc9006e687480 R08: ffffc9006e687000 R09: 0000000000003048 R10: 0000000000000480 R11: ffff8881c6083900 R12: 0000000006682516 R13: ffff8881c6095400 R14: 0000000000000016 R15: ffff8881c6b66680 FS: 0000000000000000(0000) GS:ffff88fef3c77000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fc8bda40584 CR3: 000000807c812001 CR4: 0000000008772ef0 PKRU: 55555554 Call Trace: <IRQ> ? __netif_receive_skb_list_core+0x1ca/0x250 __bnxt_poll_work+0x152/0x280 bnxt_poll_p5+0x1cd/0x480 __napi_poll+0x30/0x180 net_rx_action+0x20b/0x3b0 ? note_gp_changes+0x53/0xe0 ? tick_setup_sched_timer+0x180/0x180 ? __napi_schedule+0x9a/0xb0 ? bnxt_msix+0x24/0x30 handle_softirqs+0xdd/0x2c0 __irq_exit_rcu.llvm.3171231171502365008+0x47/0xf0 common_interrupt+0x85/0x90 </IRQ> <TASK> asm_common_interrupt+0x22/0x40 This stack trace is from a crash triggered when an out of bounds rx_tpa is dereferenced. The invalid write mentioned above is silent in this particular crash. Fix this by allocating rx_tpa with bp->max_tpa rounded up to the next power of 2 (bp->max_tpa_roundup_size) entries and masking the FW TPA ID with that size, so the wrapped ID can never index past the end of the array.

Overview

State
PUBLISHED
Assigner (CNA)
Linux
CVSS severity
HIGH
CVSS score
CVSS 8.1 / 10 8.1 8.1 / 10
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Effective score
8.1 / 10 HIGH source: CNA overview
CWE(s)
—
Reserved
2026-09-24
Published
2026-09-25 10:21 UTC
Last updated
2026-09-25 14:41 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/97xxx/CVE-2026-97570.json
Linked Threat
CVE-2026-97570 — bnxt_en: Bound SW TPA IDs to prevent crashes

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-09-25 11:17:07 UTC
NVD last modified
2026-09-25 15:17:59 UTC
NVD CVSS v3.1
CVSS 8.1 / 10 8.1 8.1 / 10 HIGH source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
NVD CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability subscore
2.2 / 10
Impact subscore
5.9 / 10

NVD / KEV / EPSS data refreshed 2026-09-26 04:31 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

Affected products (2)

VendorProductVersionsPlatforms
Linux Linux 54c28fab2fa5afd681c9c4b10f4f6da1efdd397a (affected), 54c28fab2fa5afd681c9c4b10f4f6da1efdd397a (affected) —
Linux Linux 7.1 (affected), 0 (unaffected), 7.2.7 (unaffected), 7.3-rc3 (unaffected) —

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

NVD-tagged references (2)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-97570.json.

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/broadcom/bnxt/bnxt.c",
            "drivers/net/ethernet/broadcom/bnxt/bnxt.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "05cf64d171772c65bcdee76ee7163c35d9f55a89",
              "status": "affected",
              "version": "54c28fab2fa5afd681c9c4b10f4f6da1efdd397a",
              "versionType": "git"
            },
            {
              "lessThan": "c0aceaf65b70b3c000e70dd867f3a673015f24ca",
              "status": "affected",
              "version": "54c28fab2fa5afd681c9c4b10f4f6da1efdd397a",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/broadcom/bnxt/bnxt.c",
            "drivers/net/ethernet/broadcom/bnxt/bnxt.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "lessThan": "7.1",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.7",
                  "versionStartIncluding": "7.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc3",
                  "versionStartIncluding": "7.1",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Bound SW TPA IDs to prevent crashes\n\nFW supports up to 1024 concurrent TPAs, so the FW TPA ID is in the range\n0..1023 (see commit ec4d8e7cf024 (\"bnxt_en: Add TPA ID mapping logic for\n57500 chips.\")). bnxt_alloc_agg_idx is intended to wrap the FW ID down to a\nsoftware ID which is used to index rxr->rx_tpa, and to generate a mapping\nbetween FW IDs and the wrapped software ID.\n\nOn a 57608 with firmware version 233, the firmware advertises 32\nconcurrent TPAs. As of the commit under fixes, bp->max_tpa on this NIC\nis set to 32.\n\nIf the software ID from bnxt_alloc_agg_idx is above 31, this results in\nan invalid address being loaded on this line:\n\n  tpa_info = &rxr->rx_tpa[agg_id];\n\nbecause rx_tpa is allocated with only bp->max_tpa (32) entries. Writes\nto tpa_info later in the code are out of bounds.\n\nThis bug results in a crash at boot:\n\nOops: general protection fault, kernel NULL pointer dereference 0x8: 0000 [#1] SMP NOPTI\nRIP: 0010:bnxt_rx_pkt+0xc0/0x1560\nRSP: 0018:ffffc900009b8c78 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: 0000000000000048 RCX: 0000000206682516\nRDX: ffffc900009b8db4 RSI: 0000000000000000 RDI: 01ffffff038fe1c0\nRBP: ffffc9006e687480 R08: ffffc9006e687000 R09: 0000000000003048\nR10: 0000000000000480 R11: ffff8881c6083900 R12: 0000000006682516\nR13: ffff8881c6095400 R14: 0000000000000016 R15: ffff8881c6b66680\nFS:  0000000000000000(0000) GS:ffff88fef3c77000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fc8bda40584 CR3: 000000807c812001 CR4: 0000000008772ef0\nPKRU: 55555554\nCall Trace:\n <IRQ>\n ? __netif_receive_skb_list_core+0x1ca/0x250\n __bnxt_poll_work+0x152/0x280\n bnxt_poll_p5+0x1cd/0x480\n __napi_poll+0x30/0x180\n net_rx_action+0x20b/0x3b0\n ? note_gp_changes+0x53/0xe0\n ? tick_setup_sched_timer+0x180/0x180\n ? __napi_schedule+0x9a/0xb0\n ? bnxt_msix+0x24/0x30\n handle_softirqs+0xdd/0x2c0\n __irq_exit_rcu.llvm.3171231171502365008+0x47/0xf0\n common_interrupt+0x85/0x90\n </IRQ>\n <TASK>\n asm_common_interrupt+0x22/0x40\n\nThis stack trace is from a crash triggered when an out of bounds rx_tpa\nis dereferenced. The invalid write mentioned above is silent in this\nparticular crash.\n\nFix this by allocating rx_tpa with bp->max_tpa rounded up to the next\npower of 2 (bp->max_tpa_roundup_size) entries and masking the FW TPA ID\nwith that size, so the wrapped ID can never index past the end of the\narray."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - bnxt_tpa_start() runs from bnxt_rx_pkt()/__bnxt_poll_work() in NAPI when the NIC opens a TPA aggregation for received TCP segments, so a remote sender of TCP traffic drives the out-of-bounds rx_tpa[agg_id] access with no local access needed.\nAC:H - It needs a P7 NIC (e.g. 57608) whose firmware advertises max_aggs_supported <= 32 so max_tpa stays small. The firmware, not the attacker, picks TPA_START_AGG_ID_P5; a masked ID of 32-255 then overruns rx_tpa. The attacker controls neither the hardware/firmware nor the ID choice.\nPR:N - The path runs in the RX softirq on arriving TCP segments before any socket or authentication processing, so the sender needs no credentials.\nUI:N - No victim action is needed; normal packet reception on the bnxt interface with hardware GRO/TPA enabled reaches bnxt_tpa_start().\nS:U - The corruption is in kernel heap memory next to the kzalloc'ed rx_tpa array in the same kernel authority; no guest/host or IOMMU boundary is shown to be crossed.\nC:H - bnxt_tpa_start() reads data/data_ptr/mapping from an out-of-bounds bnxt_tpa_info and posts that mapping to the RX descriptor (rx_bd_haddr), so stale heap contents get handed to the NIC and later to skb construction, exposing out-of-bounds kernel memory.\nI:H - It writes buffer pointers, the DMA mapping, and packet-derived len/rss_hash/flags2/hdr_info past the end of rx_tpa, and has the NIC DMA received packet bytes to a stale mapping read from out-of-bounds memory; this is heap memory corruption.\nA:H - The commit's reproduction shows a general protection fault oops in bnxt_rx_pkt in IRQ context during boot under normal RX traffic, which takes the machine down."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-25T14:41:16.080Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/05cf64d171772c65bcdee76ee7163c35d9f55a89"
        },
        {
          "url": "https://git.kernel.org/stable/c/c0aceaf65b70b3c000e70dd867f3a673015f24ca"
        }
      ],
      "title": "bnxt_en: Bound SW TPA IDs to prevent crashes",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-97570",
    "datePublished": "2026-09-25T10:21:55.604Z",
    "dateReserved": "2026-09-24T16:01:01.155Z",
    "dateUpdated": "2026-09-25T14:41:16.080Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}