๐Ÿ” CVE Alert

CVE-2026-31395

UNKNOWN 0.0

bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
6th

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler The ASYNC_EVENT_CMPL_EVENT_ID_DBG_BUF_PRODUCER handler in bnxt_async_event_process() uses a firmware-supplied 'type' field directly as an index into bp->bs_trace[] without bounds validation. The 'type' field is a 16-bit value extracted from DMA-mapped completion ring memory that the NIC writes directly to host RAM. A malicious or compromised NIC can supply any value from 0 to 65535, causing an out-of-bounds access into kernel heap memory. The bnxt_bs_trace_check_wrap() call then dereferences bs_trace->magic_byte and writes to bs_trace->last_offset and bs_trace->wrapped, leading to kernel memory corruption or a crash. Fix by adding a bounds check and defining BNXT_TRACE_MAX as DBG_LOG_BUFFER_FLUSH_REQ_TYPE_ERR_QPC_TRACE + 1 to cover all currently defined firmware trace types (0x0 through 0xc).

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Apr 3, 2026
Last Updated Apr 13, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
84fcd9449fd7882ddfb05ba64d75f9be2d29b2e9 < 19aa416eed9e4aaf1bbe8da0f7bd9a9be31158c8 84fcd9449fd7882ddfb05ba64d75f9be2d29b2e9 < b7c7a275447c6d4bf4a36a134682e2e4e20efd4b 84fcd9449fd7882ddfb05ba64d75f9be2d29b2e9 < 64dcbde7f8f870a4f2d9daf24ffb06f9748b5dd3
Linux / Linux
6.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/19aa416eed9e4aaf1bbe8da0f7bd9a9be31158c8 git.kernel.org: https://git.kernel.org/stable/c/b7c7a275447c6d4bf4a36a134682e2e4e20efd4b git.kernel.org: https://git.kernel.org/stable/c/64dcbde7f8f870a4f2d9daf24ffb06f9748b5dd3