HIGH Introduced in 4.16
cortina RxOverrun Panic
CVE-2026-98275
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Ack RX overrun interrupt correctly The RX overrun interrupt is reported in interrupt status register 4, but gmac_irq() acknowledges it using the RX descriptor error bit from status register 0. For GMAC0 this writes the GMAC1 overrun bit, while for GMAC1 the shift leaves no bit in the 32-bit register. Acknowledge the same per-port RX overrun bit that was detected.
02KernelScan AI Analysis
Risk summary
Devices using Cortina Gemini (StorLink SL3512/SL3516) ethernet hardware are vulnerable to a remote denial-of-service attack. An attacker who can send network traffic to the device can trigger an RX overrun condition that causes an unacknowledged interrupt storm, hanging the system. No authentication or special privileges are required.
Vulnerability analysis
The Cortina Gemini ethernet driver detects RX overrun interrupts from one status register but attempts to clear them using an incorrect bit from a different register context. For the first port this accidentally clears the second port's overrun status, and for the second port the bit shift produces no valid bit at all, so the interrupt is never acknowledged. The interrupt then fires repeatedly in a tight loop, monopolizing the CPU and hanging the system. The fix changes the acknowledgment to use the same per-port RX overrun bit that was originally detected, properly clearing the interrupt. The vulnerability is triggered by network traffic that causes an RX overrun — an attacker on the network can flood the interface with packets to induce this condition. No special privileges are required, but the device must use the specific Cortina Gemini ethernet hardware.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 4.16 | 5.10.271 | 1163cc82dcbc |
| 5.15 | 4.16 | 5.15.222 | 12a0c7bb448c |
| 6.1 | 4.16 | 6.1.189 | d72d87926ca3 |
| 6.6 | 4.16 | 6.6.158 | 472493d1d333 |
| 6.12 | 4.16 | 6.12.112 | 2f23fa11fef9 |
| 6.18 | 4.16 | 6.18.54 | 4f33e036e827 |
| 7.2 | 4.16 | 7.2.8 | d4bd67045439 |
| mainline | 4.16 | 7.3-rc4 | 1dd85662fee6 |