Executive brief
A vulnerability exists in the Linux kernel's Broadcom NetXtreme-E RDMA driver, which manages high-speed network data transfers. An error in how the system tracks hardware performance statistics can lead to memory corruption. This could allow a local user to crash the system or potentially gain unauthorized elevated privileges, impacting the overall stability and security of the server.
Technical details
An out-of-bounds (OOB) write vulnerability exists in the bnxt_re_copy_err_stats() function within the Linux kernel's RDMA subsystem. The issue was introduced when three new hardware counters (REQ_CQE_ERROR, RESP_CQE_ERROR, and RESP_REMOTE_ACCESS_ERRS) were incorrectly placed after a boundary marker (BNXT_RE_OUT_OF_SEQ_ERR) used for memory allocation. This results in the driver allocating insufficient memory for hardware statistics while still attempting to write to the extended counter indices. A local attacker can trigger this OOB write to corrupt kernel memory. The vulnerability has been patched by reordering the enum definitions to ensure all generic counters are included in the standard allocation size.
Affected products
- Linux Linux Kernel 6.18 to 6.18.4, 6.19-rc1 to 6.19-rc8
Timeline
- 2025-12-22: patched: Initial fix in mainline kernel git tree
- 2026-01-08: patched: Fix applied to stable kernel branches
- 2026-01-13: advisory: CVE-2025-71092 published