← All Advisories

CVE-2026-97569

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97569

Key Details

CVECVE-2026-97569
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

bnxt_en: Prevent queue stop with deferred completions

When the driver receives a burst of packets, it can mark a BD with the

NO_CMPL bit to defer completions. The expectation is that the last

packet in the ring will have this bit unset and the completion generated

by that packet will cleanup that packet and the ones preceding it. This

helps to reduce the number of completions fired.

The suppressed completions are controlled by the driver and the number

of packets with suppressed completions scales with the size of the ring.

SW USO packets, on the other hand, have an upper bound on the maximum

number of BDs which can be consumed which does not scale with the ring

size.

So, for small rings it is possible that: a burst of packets is handed to

the driver, the driver defers completions for all of the packets because

the number of free descriptors stays above the threshold in the driver.

Then, a USO packet arrives, but the number of BDs available is not

enough and the USO code exits early.

In this case, you end up in a state where the ring is full of packets

with their completions suppressed, which can cause the queue to stop and

never be restarted.

Assuming default CONFIG_MAX_SKB_FRAGS, this is only possible for small

rings (<= 457 descriptors, below the driver default value) when

a burst of packets fills the ring, followed by a large USO packet that

can't fit. For larger rings, the delta between the completion

suppression threshold and the BDs required for SW USO is large enough

that completions will fire and this case is unreachable.

This issue was pointed out by Sashiko and while it seems fairly unlikely

given that the queue size must be small to trigger this, it is indeed

possible.

Fix this by tracking the last BD which deferred completions and

centralizing the logic for deciding when to ring the doorbell. The NO_CMPL

bit is now cleared in bnxt_txr_db_kick(), so every doorbell site is

covered, including the SW USO early exit. This guarantees the ring always

ends in a BD which generates a completion to clean it and wake the queue. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97569
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97569