Junglewise Threat Intelligence

CVE-2026-43296: Linux kernel Marvell OcteonTX2 NIX SQM/PSE deadlock and stalls

CVE-2026-43296 · Severity: high · CVSS 7.5 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Marvell OcteonTX2 network driver within the Linux kernel can cause network hardware to stall or deadlock under heavy load. This issue affects the NIX Send Queue (SQ) manager and Packet Serialization Engine (PSE), potentially leading to a complete loss of network connectivity or significant performance degradation. An attacker could potentially trigger these hardware states to cause a denial-of-service condition.

Technical details

The vulnerability stems from hardware errata in the Marvell OcteonTX2 NIX Send Queue (SQ) manager and Packet Serialization Engine (PSE). Specifically, 'sticky mode' in the SQ manager causes stalls when multiple SQs share a single SMQ during concurrent transmissions, and the PSE can deadlock during transitions between sticky and non-sticky transmissions. Additionally, credit drops occur when certain clocks are gated. The fix involves disabling SQM sticky operations (clearing TM6 and TM11), disabling the deadlock-prone transition path (clearing TM5), and forcing the control-flow clock to remain enabled (setting TM9) via the NIX_AF_SQM_DBG_CTL_STATUS register. While the CVSS vector indicates a network attack vector, this is a hardware-level resource exhaustion/deadlock issue within the network subsystem.

Affected products

  • Linux Linux kernel octeontx2-af driver

Timeline

  • 2026-01-27: other: Patch authored by Marvell developer
  • 2026-05-08: disclosed: CVE published

References

Related threats