In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmgenet_timeout handler tries to take down all tx queues when a single queue times out. This is over zealous and causes many race conditions with queues that are still chugging along. Instead lets only restart the timed out queue.
The bcmgenet_timeout function is called when a single TX queue exceeds the transmission timeout limit. Instead of restarting only that specific queue, the handler attempts to disable all TX queues simultaneously. This causes numerous race conditions with queues that are still processing data correctly. The patch restricts the handler's action to restarting only the queue that actually timed out.
An attacker or malicious code capable of triggering race conditions can lead to breaches of confidentiality, integrity, and availability of the system — in accordance with CVSS vector (C:H/I:H/A:H). In practice, the vulnerability may result in network instability, driver failure, or further privilege escalation in the kernel.
Apply patches available in the Linux kernel stable repository, indicated in references (commits: 5393b2b5bee2, 681fdfe823b4, 7ce1c26aac3b, c270e2bec3e5, e8206538cbaf). It is recommended to update to a kernel version containing the mentioned fixes in accordance with the distribution vendor's documentation.
Linux kernel containing the bcmgenet network driver (net/ethernet/broadcom/genet); specific versions indicated in vendor references (patches available in kernel stable repository).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLinux Kernel
OSLinux4.2 – 6.1.175 (excl.)6.2 – 6.6.141 (excl.)6.7 – 6.12.91 (excl.)6.13 – 6.18.33 (excl.)6.19 – 7.0.10 (excl.)
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
RCE przez YAML deserialization w IBM Aspera Faspex
RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection
Command Injection w VMware Workspace One Access i Identity Manager