7.1

CVE-2026-90145

hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed

In the Linux kernel, the following vulnerability has been resolved:

hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed

Previously, hinic3_send_one_skb() cached the skb fragment count before
calling hinic3_tx_offload(). If hinic3_tx_csum() falls back to
skb_checksum_help() for unsupported tunnel packets, the skb may be
linearized. Continuing to build the TX descriptor with the stale
fragment count leads to a descriptor mismatch, which can trigger
out-of-bounds DMA reads or IOMMU faults.

Furthermore, the old code ignored the return value of skb_checksum_help(),
transmitting corrupted packets with incomplete checksums upon failure.

Fix this by:
1. Moving the hinic3_tx_offload() call before calculating 'num_sge' to
   ensure the correct fragment count is used if the SKB is linearized.
2. Propagating skb_checksum_help() errors and returning
   HINIC3_TX_OFFLOAD_INVALID to properly drop the skb.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 17fcb3dc12bbee8ec3e32ca1f60898f252e06b2d
Version < e794cdc5c369c1b06359e2fe03a8d9270f56bead
Status affected
Version 17fcb3dc12bbee8ec3e32ca1f60898f252e06b2d
Version < 96c3959770386b2913c62005f0d0c3151e0c01c3
Status affected
Version 17fcb3dc12bbee8ec3e32ca1f60898f252e06b2d
Version < d0c2bed6927cbfa2cb51f240b4812bf6916bce0e
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.16
Status affected
Version 0
Version < 6.16
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.053
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e794cdc5c369c1b06359e2fe03a8d9270f56bead
https://git.kernel.org/stable/c/96c3959770386b2913c62005f0d0c3151e0c01c3
https://git.kernel.org/stable/c/d0c2bed6927cbfa2cb51f240b4812bf6916bce0e