-

CVE-2026-98277

eth: fbnic: ring the doorbell if a burst ends in a drop

In the Linux kernel, the following vulnerability has been resolved:

eth: fbnic: ring the doorbell if a burst ends in a drop

fbnic_tx_map() skips the doorbell write, and the completion request,
for every packet handed to it with xmit_more set, counting on the
packet which ends the burst to publish them all. When that packet is
dropped instead - skb_put_padto(), skb_cow_head() or a DMA mapping
failure - nothing rings. The descriptors of the preceding packets stay
invisible to the HW until the next transmit on that queue, which for a
burst-then-idle workload may never come.

Remember the meta descriptor of the last packet left without a doorbell
and flush it from the error paths. The completion request has to be set
on that descriptor rather than simply writing the tail, otherwise the HW
would transmit the packets but never report a head, and the ring would
fill up and stall for good.

This is very similar to Joe's recent series of fixes for bnxt.
Not seen in real life, reproduced under QEMU with failure injection.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9a57bacd574b52b08bc2c600af6a8c7a87049ecf
Version < 60ef74357a36ed2a102a75bb68d37aa7f305b94e
Status affected
Version 9a57bacd574b52b08bc2c600af6a8c7a87049ecf
Version < 28fb764d670aa22dcbd2a02fd8fd87ae8d3563a9
Status affected
Version 9a57bacd574b52b08bc2c600af6a8c7a87049ecf
Version < 490599ab23134962a6d18a024e84541d77bdb999
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.075
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/60ef74357a36ed2a102a75bb68d37aa7f305b94e
https://git.kernel.org/stable/c/28fb764d670aa22dcbd2a02fd8fd87ae8d3563a9
https://git.kernel.org/stable/c/490599ab23134962a6d18a024e84541d77bdb999