SB2026082468 - Exposure of Resource to Wrong Sphere in Linux kernel broadcom bnxt driver
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-74697)
CWE-ID: CWE-668 - Exposure of resource to wrong sphere
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to corrupt data.
The vulnerability exists due to improper hardware interaction in the bnxt_en AGG ring handling in the bnxt driver when processing TPA data with EOP and relaxed ordering enabled. A local user can trigger network traffic processing that causes overlapping zero padding to corrupt data.
The issue was reported on some ARM systems using 57508 (P5) chips, and it occurs when TPA is enabled.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/410da4428b1f47bf9a84bdc0bcaa089d73ba2048
- https://git.kernel.org/stable/c/68c181af7cd1ca9cbf29acd95911073bfd3c6397
- https://git.kernel.org/stable/c/7aee22a35978b44784612c156e358e375ddf5d16
- https://git.kernel.org/stable/c/aab3b5f4d8ec8598606ee011e219ef824ae25ca0
- https://git.kernel.org/stable/c/b61c4911204a0a2f900e538d64ceb608f6c9614d
- https://git.kernel.org/stable/c/c1962ab4645a914a91ff492735881150ddc8a79e
- https://git.kernel.org/stable/c/c3faf548a00f4c17100cc9204746975fa46a73b9