Junglewise Threat Intelligence

CVE-2026-89582: Linux kernel bnx2x double free in init_firmware error path

CVE-2026-89582 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The bnx2x network driver in the Linux kernel contains a double-free memory error in its firmware initialization error handling. If firmware initialization fails, the cleanup code frees the same memory buffers twice, which could lead to kernel memory corruption or denial of service when the driver unloads or recovers from an initialization error.

Technical details

The vulnerability is a double-free memory error (CWE-415) in the bnx2x driver's bnx2x_init_firmware() function. When firmware loading fails, the error path frees three pointers (bp->init_ops, bp->init_data, and bp->init_ops_offsets) without setting them to NULL. Later, when bnx2x_release_firmware() is called during driver cleanup or removal, it unconditionally frees the same three pointers again, causing a double-free. The bug occurs in the kernel driver code, locally on systems running the bnx2x driver. The fix sets each freed pointer to NULL in the error path, making subsequent kfree(NULL) calls safe no-ops. This is a low-risk kernel memory management bug rather than a remote exploitation vector.

Affected products

  • Linux kernel 2.6.x through 7.x (bnx2x driver in drivers/net/ethernet/broadcom/bnx2x)

Timeline

  • 2026-09-11: disclosed: CVE-2026-89582 published
  • 2026-08-15: patched: Patch committed by Jiangshan Yi
  • 2026-09-14: patched: Merged into stable kernel by Greg Kroah-Hartman

References

Related threats