PT-2026-90128 · Linux · Linux

CVE-2026-80998

·

Publicado

2026-09-11

·

Atualizado

2026-09-11

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
net: bnxt: ring the doorbell when SW USO exits early
When a burst of packets is handed down to the driver, the driver defers the doorbell to the end by setting txr->kick pending = 1. The normal TX path handles this, but the SW USO path can miss it if it returns early.
If bnxt sw udp gso xmit runs but returns early with NETDEV TX BUSY and txr->kick pending was previously set to 1, then the TX queue can stall because the driver wrote some BDs but never wrote the doorbell. The device won't know to do the TX which would generate the completion that would wake the queue back up.
Simplify bnxt sw udp gso xmit to set txr->kick pending in its success case and check the flag on return. The added check after bnxt sw udp gso xmit returns ensures that any pending doorbells are written handling both successful USO and any early returns, which prevents the TX queue stall mentioned above.
This TX queue stall was observed on a production system with a netdev TX watchdog informing about the queue stall.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-80998

Produtos afetados

Linux