CRITICAL🇵🇱 Wersja polska

CVE-2026-53088

CVSS 9.8pub. 2026-06-24upd. 2026-07-23

In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb The write_ptr points to the next open tx_cb. We want to return the tx_cb that gets rewinded, so we must rewind the pointer first then return the tx_cb that it points to. That way the txcb can be correctly cleaned up.

🤖 AI Analysis
How it works

The write_ptr pointer points to the next free space in the tx_cb transmit buffer. In the bcmgenet_put_txcb function, the pointer was first returned and only then rewound, which caused an incorrect buffer element to be returned. Correct operation requires first rewinding the pointer and then returning the tx_cb it points to, so it can be properly cleared.

Impact

A remote attacker, without authentication, can cause improper memory management in the network driver, which may result in violation of confidentiality, data integrity, and system availability.

Mitigation & patch

Patches available from the manufacturer should be applied according to references — fixes have been published in the Linux kernel stable repository under the indicated commits.

Who is affected

Linux kernel versions containing the bcmgenet driver — specific versions indicated in the manufacturer's references (commits available in the kernel stable repository).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Linux Kernel

    OS
    Linux
    4.134.13.1 – 5.10.258 (excl.)5.11 – 5.15.209 (excl.)5.16 – 6.1.175 (excl.)3.16.50 – 3.17 (excl.)6.7 – 6.12.91 (excl.)6.13 – 6.18.33 (excl.)6.19 – 7.0.10 (excl.)6.2 – 6.6.141 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓same product

RCE przez YAML deserialization w IBM Aspera Faspex

CVE-2022-22954CRITICAL9.8⚠ KEVPL ✓same product

RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection

CVE-2020-4006CRITICAL9.1⚠ KEVPL ✓same product

Command Injection w VMware Workspace One Access i Identity Manager