PT-2026-6111 · Unknown+2 · Bnxt Init One+3
CVE-2026-23041
·
Published
2026-01-01
·
Updated
2026-02-10
CVSS v2.0
4.3
Medium
| Vector | AV:A/AC:H/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.19-rc3
Description
The Broadcom network driver in the Linux kernel contains a flaw related to PTP (Precision Time Protocol) handling. Specifically, a NULL pointer dereference can occur in the
bnxt ptp enable() function during error cleanup when bnxt init one() fails. This happens because the hardware resource DMA pool is freed before the PTP clock is unregistered, leading to a crash when attempting to allocate memory from the freed pool. The issue stems from the order of operations during error handling, where PTP events are disabled after the DMA pool has been destroyed.Recommendations
Update to a version of the Linux kernel that is later than 6.19-rc3.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Broadcom Network Driver
Linux Kernel
Bnxt Init One
Bnxt Ptp Enable