Executive brief
A flaw was discovered in the Linux kernel's Broadcom GENET network driver. This issue involves an 'off-by-one' error during network data transmission processing, which could prevent the system from correctly cleaning up memory used for network traffic. While primarily a technical bug, such issues can sometimes lead to system instability or memory exhaustion if triggered repeatedly.
Technical details
An off-by-one vulnerability exists in the bcmgenet_put_txcb function within the drivers/net/ethernet/broadcom/genet/bcmgenet.c component of the Linux kernel. The write_ptr, which tracks the next available transmit control block (tx_cb), was being used to return a pointer before the necessary pointer decrement (rewind) occurred. This logic error resulted in the function returning the wrong control block, preventing proper unmapping and cleanup of transmit fragments. An attacker could potentially exploit this to cause a memory leak or kernel instability. The issue has been resolved by reordering the pointer rewind logic to ensure the correct tx_cb is returned for cleanup.
Affected products
- Linux Linux 3.16.50 to 3.17, 4.13, 5.10.258, 5.15.209
Timeline
- 2026-06-24: disclosed: CVE published by kernel.org
- 2026-06-24: advisory: NVD record created
References
- https://git.kernel.org/stable/c/14e9f86564fff7bcf7f45c1b69080e837b31d185
- https://git.kernel.org/stable/c/29394f722f620281f2ee9a47f947734e53d72c90
- https://git.kernel.org/stable/c/2a74590170427a3ca7cc4bb8690cdd559129c29c
- https://git.kernel.org/stable/c/4cab761fc51c65aef741fcece4a18f3554edbc09
- https://git.kernel.org/stable/c/57f3f53d2c9c5a9e133596e2f7bc1c50688a6d38
- https://git.kernel.org/stable/c/72df896e31ddd06fcc5a789f025ad7a62a18bc9b
- https://git.kernel.org/stable/c/85f34ec320d3881badfd4edc5fee5cd5012bb54d