Junglewise Threat Intelligence

CVE-2026-53177: Linux Kernel bnxt_en NULL pointer dereference in PCIe error recovery

CVE-2026-53177 · Severity: info · CVSS 0 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Broadcom NetXtreme-E (bnxt_en) network driver for the Linux kernel could cause a system crash. This occurs when the system attempts to perform PCIe error recovery on a network interface that is currently closed, leading to a kernel failure. This could result in a denial-of-service (DoS) for the affected server.

Technical details

A NULL pointer dereference exists in the bnxt_en driver's error handling path. When a PCIe error is detected, the bnxt_io_error_detected() callback invokes bnxt_disable_int_sync(), which attempts to map completion rings to IRQs using the bp->bnapi structure. Because this structure is only allocated when the NIC is open and is freed when it is closed, triggering error recovery on a closed interface results in a NULL pointer dereference. The fix introduces a check for the NULL state of bp->bnapi before proceeding with IRQ synchronization. This issue affects various stable branches of the Linux kernel and has been patched in multiple upstream versions.

Affected products

  • Linux Linux kernel 4.17 to 6.14.y

Timeline

  • 2026-06-25: advisory: CVE-2026-53177 published by NVD
  • 2026-06-19: patched: Fix committed to Linux stable tree by Greg Kroah-Hartman

References

Related threats