← All Advisories

CVE-2026-97571

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97571

Key Details

CVECVE-2026-97571
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

bnxt_en: Propagate TPA buffer allocation failures in bnxt_queue_mem_alloc()

bnxt_alloc_one_tpa_info_data() returns -ENOMEM as soon as one allocation

fails. This leaves the remaining rxr->rx_tpa[] entries zeroed.

bnxt_queue_mem_alloc() discards that return value, so the partially

initialized ring is installed by bnxt_queue_start().

Since the agg_id is picked by the hardware and bnxt_alloc_agg_idx maps

it to a SW index in rxr->rx_tpa[], it is possible that an uninitialized

slot can be chosen which would hand a zero DMA address to the device.

Fix this by checking the return value of bnxt_alloc_one_tpa_info_data

and unwinding, freeing the ring buffers. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97571
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97571