PT-2026-6111 · Unknown+2 · Bnxt Init One+3

CVE-2026-23041

·

Published

2026-01-01

·

Updated

2026-02-10

CVSS v2.0

4.3

Medium

VectorAV:A/AC:H/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.19-rc3
Description The Broadcom network driver in the Linux kernel contains a flaw related to PTP (Precision Time Protocol) handling. Specifically, a NULL pointer dereference can occur in the bnxt ptp enable() function during error cleanup when bnxt init one() fails. This happens because the hardware resource DMA pool is freed before the PTP clock is unregistered, leading to a crash when attempting to allocate memory from the freed pool. The issue stems from the order of operations during error handling, where PTP events are disabled after the DMA pool has been destroyed.
Recommendations Update to a version of the Linux kernel that is later than 6.19-rc3.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13793
CVE-2026-23041

Affected Products

Broadcom Network Driver
Linux Kernel
Bnxt Init One
Bnxt Ptp Enable