7.5

CVE-2026-93830

net: stmmac: xgmac2: disable RBUE in default RX interrupt mask

In the Linux kernel, the following vulnerability has been resolved:

net: stmmac: xgmac2: disable RBUE in default RX interrupt mask

Enabling the RX Buffer Unavailable (RBUE) interrupt is counterproductive
and can trigger a MAC interrupt storm under heavy RX pressure. When the
DMA runs out of RX descriptors it fires RBUE continuously until software
refills the ring.

However, RBUE is redundant: the normal RX completion interrupt (RIE)
already triggers NAPI, which processes completed descriptors and refills
the ring, causing the DMA to resume. The RBUE handler itself only sets
handle_rx - the same outcome as RIE.

On Agilex5 under heavy RX pressure, the MAC interrupt (which includes
RBUE) was observed firing 1,821,811,555 times against only 2,618,627
actual RX completions - a ~695x ratio - confirming the severity of the
storm.

RBUE does not provide OOM recovery. If page_pool is exhausted,
stmmac_rx_refill() cannot advance the DMA tail pointer, the DMA stays
suspended, and RBUE fires again on the next NAPI completion - a storm
with no forward progress. This patch trades that storm for a clean
stall with the same RX outcome. Proper OOM recovery is a pre-existing
gap outside the scope of this fix.

Note: as a consequence of disabling RBUE, the rx_buf_unav_irq ethtool
counter will always read 0 on XGMAC2 devices. This behaviour is already
inconsistent across DWMAC core versions.

Remove RBUE from XGMAC_DMA_INT_DEFAULT_EN and XGMAC_DMA_INT_DEFAULT_RX
to prevent the interrupt storm while keeping normal RX handling intact.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version d6ddfacd95c79d43465d4a85dffb1c9beca343a9
Version < 8c9d57b5dc098b84631d0b3559c84c499ea2170a
Status affected
Version d6ddfacd95c79d43465d4a85dffb1c9beca343a9
Version < 7a10e54e42a8f73a8d731f5a281fc06bb41b9250
Status affected
Version d6ddfacd95c79d43465d4a85dffb1c9beca343a9
Version < 6b3b91433d5f4eae6865cdaa96f40cd67849e1f6
Status affected
Version d6ddfacd95c79d43465d4a85dffb1c9beca343a9
Version < 74dbb85a6a254b5fc1f265a6cd61b2ba9d9221d7
Status affected
Version d6ddfacd95c79d43465d4a85dffb1c9beca343a9
Version < 0b1a5d3647ce07c27a9fffefc11a8cbf7d7b25ce
Status affected
Version d6ddfacd95c79d43465d4a85dffb1c9beca343a9
Version < 87e2826ed2058747ddf014c082569a46bfadd96b
Status affected
Version d6ddfacd95c79d43465d4a85dffb1c9beca343a9
Version < d3265c19b35d036bba327b36b5366bee76b0157c
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.19
Status affected
Version 0
Version < 4.19
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.342
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0b1a5d3647ce07c27a9fffefc11a8cbf7d7b25ce
https://git.kernel.org/stable/c/87e2826ed2058747ddf014c082569a46bfadd96b
https://git.kernel.org/stable/c/d3265c19b35d036bba327b36b5366bee76b0157c
https://git.kernel.org/stable/c/6b3b91433d5f4eae6865cdaa96f40cd67849e1f6
https://git.kernel.org/stable/c/74dbb85a6a254b5fc1f265a6cd61b2ba9d9221d7
https://git.kernel.org/stable/c/7a10e54e42a8f73a8d731f5a281fc06bb41b9250
https://git.kernel.org/stable/c/8c9d57b5dc098b84631d0b3559c84c499ea2170a