Executive brief
The Linux kernel's Texas Instruments ICSSG Ethernet driver incorrectly attempts to read firmware statistics on hardware that lacks the optional packet acceleration (PA) stats block. This causes thousands of error log messages to be generated during normal operation and corrupts network statistics counters (rx_errors, rx_dropped, tx_dropped) reported to administrators, impacting visibility into actual network health and making troubleshooting difficult.
Technical details
The vulnerability is a missing guard check in the icssg_ndo_get_stats64() function in drivers/net/ethernet/ti/icssg/icssg_common.c. The function unconditionally calls emac_get_stat_by_name() with firmware PA stat names regardless of whether the PA stats block is present (checked via emac->prueth->pa_stats being non-NULL). When pa_stats is NULL, the lookup fails, emac_get_stat_by_name() returns -EINVAL, and this occurs repeatedly as the networking stack regularly polls stats. The int(-EINVAL) return value is implicitly widened to a near-ULLONG_MAX unsigned value when accumulated into the 64-bit stats structure, silently corrupting reported counters. The fix adds a guard `if (!emac->prueth->pa_stats) return;` before attempting PA stat lookups, consistent with how other code paths in the driver already handle this condition. The patch is available in Linux kernel upstream and stable branches.
Affected products
- Linux Linux kernel versions with commit 0d15a26b247d (ICSSG FW Stats) and later
Timeline
- 2026-06-22: disclosed
- 2026-06-22: patched: Fix merged upstream (commit 27b9daba50609335db6ca81e4cccf50ded21ec76)
- 2026-07-24: patched: Fix backported to stable kernel (commit 121c5f31c3fb70d4a23e8a084f5cb8b3ec63be8d)