KernelScan.io

HIGH Introduced in 7.1

bnxt_en TpaId OOB

CVE-2026-97570

CVSS 8.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI9.8CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Bound SW TPA IDs to prevent crashes FW supports up to 1024 concurrent TPAs, so the FW TPA ID is in the range 0..1023 (see commit ec4d8e7cf024 ("bnxt_en: Add TPA ID mapping logic for 57500 chips.")). bnxt_alloc_agg_idx is intended to wrap the FW ID down to a software ID which is used to index rxr->rx_tpa, and to generate a mapping between FW IDs and the wrapped software ID. On a 57608 with firmware version 233, the firmware advertises 32 concurrent TPAs. As of the commit under fixes, bp->max_tpa on this NIC is set to 32. If the software ID from bnxt_alloc_agg_idx is above 31, this results in an invalid address being loaded on this line: tpa_info = &rxr->rx_tpa[agg_id]; because rx_tpa is allocated with only bp->max_tpa (32) entries. Writes to tpa_info later in the code are out of bounds. This bug results in a crash at boot: Oops: general protection fault, kernel NULL pointer dereference 0x8: 0000 [#1] SMP NOPTI RIP: 0010:bnxt_rx_pkt+0xc0/0x1560 RSP: 0018:ffffc900009b8c78 EFLAGS: 00010246 RAX: 0000000000000000 RBX: 0000000000000048 RCX: 0000000206682516 RDX: ffffc900009b8db4 RSI: 0000000000000000 RDI: 01ffffff038fe1c0 RBP: ffffc9006e687480 R08: ffffc9006e687000 R09: 0000000000003048 R10: 0000000000000480 R11: ffff8881c6083900 R12: 0000000006682516 R13: ffff8881c6095400 R14: 0000000000000016 R15: ffff8881c6b66680 FS: 0000000000000000(0000) GS:ffff88fef3c77000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fc8bda40584 CR3: 000000807c812001 CR4: 0000000008772ef0 PKRU: 55555554 Call Trace: <IRQ> ? __netif_receive_skb_list_core+0x1ca/0x250 __bnxt_poll_work+0x152/0x280 bnxt_poll_p5+0x1cd/0x480 __napi_poll+0x30/0x180 net_rx_action+0x20b/0x3b0 ? note_gp_changes+0x53/0xe0 ? tick_setup_sched_timer+0x180/0x180 ? __napi_schedule+0x9a/0xb0 ? bnxt_msix+0x24/0x30 handle_softirqs+0xdd/0x2c0 __irq_exit_rcu.llvm.3171231171502365008+0x47/0xf0 common_interrupt+0x85/0x90 </IRQ> <TASK> asm_common_interrupt+0x22/0x40 This stack trace is from a crash triggered when an out of bounds rx_tpa is dereferenced. The invalid write mentioned above is silent in this particular crash. Fix this by allocating rx_tpa with bp->max_tpa rounded up to the next power of 2 (bp->max_tpa_roundup_size) entries and masking the FW TPA ID with that size, so the wrapped ID can never index past the end of the array.

02

Engine v0.6.0

Risk summary

Systems with Broadcom bnxt_en network adapters (notably 57608 with certain firmware versions) are vulnerable to out-of-bounds heap writes when processing received TCP traffic that triggers TPA aggregation. The driver masks firmware TPA IDs to a range larger than the allocated array, causing silent heap corruption and potentially a kernel crash. Any network attacker who can send traffic to the affected NIC can trigger this without authentication.

Affecteddrivers/net/ethernet/broadcom/bnxt/bnxt.c (bnxt_en)

Vulnerability analysis

The Broadcom network driver allocates an array to track packet aggregation state for each receive ring, sized to the number of contexts the firmware advertises. However, the driver wraps firmware-supplied aggregation IDs using a mask based on a much larger hard-coded maximum, which can produce indices well beyond the allocated array. When the firmware assigns an ID that wraps above the array bounds, the driver writes aggregation state past the end of the buffer, corrupting adjacent heap memory. In the observed crash, this also causes the driver to dereference an invalid pointer and panic the kernel. The fix sizes the array to the next power of two and masks the incoming firmware ID to that same size, so the index can never exceed the array bounds. This affects systems with certain Broadcom network adapters whose firmware advertises a small number of aggregation contexts, and is triggered by ordinary received network traffic that the hardware coalesces.

03

BranchIntroducedFixed inPatch commit
7.27.17.2.705cf64d17177
mainline7.17.3-rc3c0aceaf65b70