Junglewise Threat Intelligence

CVE-2026-31395: Linux Kernel bnxt_en out-of-bounds access in async event handler

CVE-2026-31395 · Severity: high · CVSS 7.1 · Published 2026-04-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Broadcom NetXtreme-E (bnxt_en) network driver for the Linux kernel could allow a compromised or malicious network card to crash the system or corrupt memory. The driver fails to verify data sent from the hardware before using it to access internal memory buffers. This could lead to a total system failure or unauthorized access to sensitive kernel information.

Technical details

An out-of-bounds (OOB) access vulnerability exists in the bnxt_en driver's DBG_BUF_PRODUCER async event handler. The function bnxt_async_event_process() extracts a 16-bit 'type' field from DMA-mapped completion ring memory and uses it as an index into the bp->bs_trace[] array without bounds validation. A malicious or compromised NIC can provide an arbitrary index value, leading to OOB reads or writes in kernel heap memory via bnxt_bs_trace_check_wrap(). This can result in kernel memory corruption or a system crash (DoS). The issue has been patched by adding explicit bounds checking against the ARRAY_SIZE of the trace buffer.

Affected products

  • Linux Linux Kernel 6.13 to 6.18.20, 6.19 to 6.19.10, 7.0-rc1 to 7.0-rc4

Timeline

  • 2026-03-14: other: Patch authored
  • 2026-04-03: disclosed
  • 2026-04-03: advisory

References

Related threats