SB20260827137 - Out-of-bounds read in Linux kernel ethernet ti driver
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-74737)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds memory access in the am65-cpsw-nuss packet reception path when processing RX DMA descriptor metadata containing the source tag. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue occurs because the driver uses the full 16-bit source tag as the port identifier even though only the lower 8 bits represent the MAC port ID, while the upper 8 bits are hardware-reserved and may contain arbitrary values.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/14fc40bf28390e0ebee6a072457c36b82c614100
- https://git.kernel.org/stable/c/1c0e35ce761131f82062222779d8574849790892
- https://git.kernel.org/stable/c/36a05d2820077bb3955acb8111e1041d39148037
- https://git.kernel.org/stable/c/46a8e084a159e638ac2728e96980b65d752d65fd
- https://git.kernel.org/stable/c/551688b410d3fb0dae7739724422f268cd9446d6
- https://git.kernel.org/stable/c/72e4e3d7efc3b7d85f86abbe8b94f8e45074abe3
- https://git.kernel.org/stable/c/914e0100df3435bd14d09f397238e891cf9b7dce
- https://git.kernel.org/stable/c/9a220225efd6f58350bbb53fe70bdec08519267f