Junglewise Threat Intelligence

CVE-2026-53087: Linux Kernel bcmgenet resource leak in tx queue reclamation

CVE-2026-53087 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Broadcom GENET network driver. When the system attempts to clear out the network transmission queue, it fails to properly track available memory resources and notify the networking subsystem about dropped data. This could lead to resource exhaustion or inconsistent network states on affected hardware.

Technical details

A vulnerability in the bcmgenet driver (drivers/net/ethernet/broadcom/genet/bcmgenet.c) occurs during the tx queue reclamation process. When the driver fast-forwards the write pointer to drop in-flight data, it fails to increment the free buffer descriptor (BD) count and does not call netdev_tx_reset_queue to synchronize the state with the network stack. This results in a leak of free_bds and potential inconsistencies in the netdev queue state. The issue was introduced in the logic supporting the reclamation of unsent Tx packets and has been patched in multiple stable branches including 6.18.33 and 7.0.10.

Affected products

  • Linux Linux 6.15 to 7.1

Timeline

  • 2026-04-06: other: Patch authored
  • 2026-06-24: advisory: CVE published

References