KernelScan.io

HIGH Introduced in 4.16

cortina RxOverrun Panic

CVE-2026-98275

CVSS 7.5 / 10.0 KernelScan AI

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

01

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Ack RX overrun interrupt correctly The RX overrun interrupt is reported in interrupt status register 4, but gmac_irq() acknowledges it using the RX descriptor error bit from status register 0. For GMAC0 this writes the GMAC1 overrun bit, while for GMAC1 the shift leaves no bit in the 32-bit register. Acknowledge the same per-port RX overrun bit that was detected.

02

Engine v0.7.0

Risk summary

Devices using Cortina Gemini (StorLink SL3512/SL3516) ethernet hardware are vulnerable to a remote denial-of-service attack. An attacker who can send network traffic to the device can trigger an RX overrun condition that causes an unacknowledged interrupt storm, hanging the system. No authentication or special privileges are required.

Affecteddrivers/net/ethernet/cortina/gemini.c (Cortina Gemini Ethernet driver)

Vulnerability analysis

The Cortina Gemini ethernet driver detects RX overrun interrupts from one status register but attempts to clear them using an incorrect bit from a different register context. For the first port this accidentally clears the second port's overrun status, and for the second port the bit shift produces no valid bit at all, so the interrupt is never acknowledged. The interrupt then fires repeatedly in a tight loop, monopolizing the CPU and hanging the system. The fix changes the acknowledgment to use the same per-port RX overrun bit that was originally detected, properly clearing the interrupt. The vulnerability is triggered by network traffic that causes an RX overrun — an attacker on the network can flood the interface with packets to induce this condition. No special privileges are required, but the device must use the specific Cortina Gemini ethernet hardware.

03

BranchIntroducedFixed inPatch commit
5.104.165.10.2711163cc82dcbc
5.154.165.15.22212a0c7bb448c
6.14.166.1.189d72d87926ca3
6.64.166.6.158472493d1d333
6.124.166.12.1122f23fa11fef9
6.184.166.18.544f33e036e827
7.24.167.2.8d4bd67045439
mainline4.167.3-rc41dd85662fee6