PT-2026-52310 · Linux+2 · Linux Kernel+2

CVE-2026-53215

·

Published

2026-06-25

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the mvpp2 network driver where the RX error path returns the current descriptor buffer to the hardware Buffer Manager (BM) pool. This action is only valid while the driver maintains ownership of the buffer. If the mvpp2 rx refill() function fails after the buffer has been passed to XDP (eXpress Data Path) or attached to an skb (socket buffer), the buffer may have already been recycled, redirected, or queued. Returning such a buffer to the BM pool allows the hardware to perform Direct Memory Access (DMA) into memory that is no longer owned by the RX ring.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-53215
ECHO-A6E4-6DD5-0786
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22809-1
SUSE-SU-2026:22810-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:22903-1
SUSE-SU-2026:22904-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8629-1
USN-8629-2
USN-8629-3
USN-8630-1
USN-8630-2
USN-8630-3
USN-8630-4
USN-8630-5
USN-8631-1
USN-8631-2
USN-8631-3
USN-8631-4
USN-8637-1
USN-8656-1
USN-8660-1
USN-8661-1
USN-8661-2
USN-8661-3
USN-8661-4
USN-8663-1
USN-8664-1
USN-8728-1
USN-8748-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu