Executive brief
A vulnerability in the Linux kernel's Marvell MVPP2 network driver can cause a system crash when certain network settings, such as the Maximum Transmission Unit (MTU), are modified. This issue occurs on hardware configurations where specific memory resources are not defined in the system's device tree. An exploit could lead to a denial-of-service condition, impacting the availability of the affected device or server.
Technical details
A NULL pointer dereference exists in the mvpp2_bm_switch_buffers() function within the Marvell MVPP2 ethernet driver (drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c). The vulnerability is triggered when the driver attempts to update flow control registers via mvpp2_cm3_read() or mvpp2_cm3_write() without verifying if the CM3 SRAM resource (priv->cm3_base) was successfully mapped from the device tree. Local attackers or automated system processes triggering an MTU change that crosses the jumbo frame threshold can cause a kernel panic. The fix introduces a guard check for priv->global_tx_fc before attempting to access these registers, ensuring hardware access only occurs when the resource is present.
Affected products
- Linux Linux Kernel Fixed in 6.1.x, 6.6.x, 6.12.x, 6.13.x, 6.14.x
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6
Timeline
- 2026-03-16: disclosed: Initial patch submission by Muhammad Hammad Ijaz
- 2026-03-25: patched: Patches merged into various stable kernel branches
- 2026-04-03: advisory: CVE published to NVD
References
- https://git.kernel.org/stable/c/0cfcd31f98fc608dc9406bff3fee3a9dd364d014
- https://git.kernel.org/stable/c/7bd20f4b3ef3044dc55acd5b8ef748a70d29d03f
- https://git.kernel.org/stable/c/7df2b50cae1a76cbb90b294f3edb61e3e10bf2e9
- https://git.kernel.org/stable/c/8a63baadf08453f66eb582fdb6dd234f72024723
- https://git.kernel.org/stable/c/8baced53a35fc9710f80d6ca016a2c418dc3231f
- https://git.kernel.org/stable/c/da089f74a993f846685067b14158cb41b879ff29
- https://git.kernel.org/stable/c/ff0c54f088f7ab91dbbf47cf8244460f99122750