Executive brief
A vulnerability in the Broadcom NetXtreme-E (bnxt_en) network driver for the Linux kernel could cause a system crash. This occurs when the system attempts to perform PCIe error recovery on a network interface that is currently closed, leading to a kernel failure. This could result in a denial-of-service (DoS) for the affected server.
Technical details
A NULL pointer dereference exists in the bnxt_en driver's error handling path. When a PCIe error is detected, the bnxt_io_error_detected() callback invokes bnxt_disable_int_sync(), which attempts to map completion rings to IRQs using the bp->bnapi structure. Because this structure is only allocated when the NIC is open and is freed when it is closed, triggering error recovery on a closed interface results in a NULL pointer dereference. The fix introduces a check for the NULL state of bp->bnapi before proceeding with IRQ synchronization. This issue affects various stable branches of the Linux kernel and has been patched in multiple upstream versions.
Affected products
- Linux Linux kernel 4.17 to 6.14.y
Timeline
- 2026-06-25: advisory: CVE-2026-53177 published by NVD
- 2026-06-19: patched: Fix committed to Linux stable tree by Greg Kroah-Hartman
References
- https://git.kernel.org/stable/c/08e57d014ea19f303d5d57a849beb846f37788b7
- https://git.kernel.org/stable/c/1a418ad0e5e525d1d117dd1601681f75455af320
- https://git.kernel.org/stable/c/3884976f87448e269908ae61bd5d62d54ce9c0c7
- https://git.kernel.org/stable/c/580844a9683afe7974856dd5b7886447435b3474
- https://git.kernel.org/stable/c/59c5a3e69c7630a811565937e64be70b08436761
- https://git.kernel.org/stable/c/964b1c3eb71afe58bb61c8b984164447e000ae8a
- https://git.kernel.org/stable/c/d930276f2cddd0b7294cac7a8fe7b877f6d9e08d