Unchecked Return Value in Linux kernel - CVE-2026-97571
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause the device to use a zero DMA address.
The vulnerability exists due to an unchecked return value in bnxt_queue_mem_alloc() when allocating TPA buffer information. A local user can trigger a TPA buffer allocation failure to cause the device to use a zero DMA address.
An uninitialized rx_tpa[] slot must be selected by the hardware.