KernelScan.io

HIGH Introduced in 4.7

stmmac TSO TxRing Corruption

CVE-2026-97953

CVSS 7.0 / 10.0 NVD

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

KernelScan AI9.8CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TX descriptor availability check for TSO traffic stmmac_tso_xmit() estimates the number of free TX descriptors required by a TSO skb as: (skb->len - proto_hdr_len) / TSO_MAX_BUFF_SIZE + 1 which assumes the payload is split into TSO_MAX_BUFF_SIZE chunks. This underestimates the descriptors actually consumed by stmmac_tso_allocator(), since each fragment is mapped individually and so it needs at least one descriptor regardless of its size. Moreover, one descriptor is used for the L2/L3/L4 headers and, when the MSS changes, one more is consumed for the MSS context descriptor. For a highly fragmented TSO skb the check can therefore pass even when the ring has too few free slots. stmmac_tso_allocator() then writes past the available descriptors, overwriting descriptors still owned by the DMA engine, corrupting the TX ring. Add stmmac_tso_get_num_desc() to compute the exact number of descriptors needed for the header, the linear payload and each fragment, plus the MSS context descriptor when required, and use it in the availability check.

02

Engine v0.6.0

Risk summary

Devices using stmmac Ethernet controllers are vulnerable to TX descriptor ring corruption when sending highly fragmented TSO traffic. A remote attacker who can cause the device to transmit TCP responses can trigger arbitrary memory corruption, potentially achieving code execution or crashing the kernel. No authentication or privileges on the target device are required if any network service is exposed.

Affecteddrivers/net/ethernet/stmicro/stmmac/stmmac_main.c (stmmac)

Vulnerability analysis

The stmmac Ethernet driver underestimates the number of TX descriptors needed when transmitting highly fragmented TCP Segmentation Offload traffic. The original availability check assumes the payload splits into fixed-size chunks, but each packet fragment actually consumes at least one descriptor, plus additional descriptors for headers and MSS context updates. When a highly fragmented TSO packet is queued and the TX ring is near capacity, the flawed check passes and the driver writes past the available descriptors, corrupting the ring and overwriting entries still owned by the DMA engine. The fix replaces the rough estimate with an exact descriptor count that accounts for the header, the linear payload, every individual fragment, and the MSS context descriptor when the MSS changes. This vulnerability is reachable from the network by any remote host that can make the device transmit TSO-segmented traffic—for example, by connecting to a TCP service and receiving large responses—or locally by any user able to send traffic through a stmmac interface. It requires stmmac-compatible Ethernet hardware to be present and active.

03

BranchIntroducedFixed inPatch commit
6.124.76.12.111ffa6d2481bc1
6.184.76.18.53c28175220f80
7.24.77.2.765820fc743ea
mainline4.77.3-rc35e38d732ec67