7.8

CVE-2026-98052

net: bcmasp: clear txcb->last before writing each descriptor

In the Linux kernel, the following vulnerability has been resolved:

net: bcmasp: clear txcb->last before writing each descriptor

bcmasp_xmit() only wrote txcb->last = true for the final fragment
of an SKB; non-final fragments left the field untouched.  If a
descriptor slot was reused while it still held a stale true from
a previous SKB (possible when tx_spb_ring_full() underreported
fullness), bcmasp_tx_reclaim() would see last == true mid-SKB and
call dev_consume_skb_any() prematurely, freeing the sk_buff while
its remaining fragments were still in flight.

Unconditionally clear txcb->last before the conditional set so every
descriptor slot starts from a known false state regardless of what a
prior transmission left behind.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.6 < 6.6.158
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.111
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.53
Linux ≫ Linux Kernel Version >= 6.19 < 7.2.7
Linux ≫ Linux Kernel Version 7.3 Update rc1
Linux ≫ Linux Kernel Version 7.3 Update rc2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.021
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9b26b54861ce05307d39a54ddedddf8747419614
Patch
https://git.kernel.org/stable/c/47a5cecca925ceb175d5adf712e667acf78f475f
Patch
https://git.kernel.org/stable/c/17e6ad484dea5ddf1c4a3d6ec77a5929161234de
Patch
https://git.kernel.org/stable/c/18e5e0ec0e9282c897e2aa81a3e43ccaee03b003
Patch
https://git.kernel.org/stable/c/1e213ba7cb3b9dd97ac2e0a1054e6d0d1d91f5bc
Patch