Back

MEDIUM

net: ethernet: ti: Fix return type of netcp_ndo_start_xmit()

Published Oct 4, 2025

Description

With clang's kernel control flow integrity (kCFI, CONFIG_CFI_CLANG), indirect call targets are validated against the expected function pointer prototype to make sure the call target is valid to help mitigate ROP attacks. If they are not identical, there is a failure at run time, which manifests as either a kernel panic or thread getting killed. A proposed warning in clang aims to catch these at compile time, which reveals:

drivers/net/ethernet/ti/netcp_core.c:1944:21: error: incompatible function pointer types initializing 'netdev_tx_t (*)(struct sk_buff *, struct net_device *)' (aka 'enum netdev_tx (*)(struct sk_buff *, struct net_device *)') with an expression of type 'int (struct sk_buff *, struct net_device *)' [-Werror,-Wincompatible-function-pointer-types-strict] .ndo_start_xmit = netcp_ndo_start_xmit, ^~~~~~~~~~~~~~~~~~~~ 1 error generated.

->ndo_start_xmit() in 'struct net_device_ops' expects a return type of 'netdev_tx_t', not 'int'. Adjust the return type of netcp_ndo_start_xmit() to match the prototype's to resolve the warning and CFI failure.

Affected products

Remediation

Red Hat statement

The netcp_ndo_start_xmit function is declared with a return type of 'int' instead of the expected 'netdev_tx_t' enum. When CONFIG_CFI_CLANG is enabled, the kernel validates indirect function call targets against their expected prototypes to prevent control-flow hijacking attacks. The type mismatch causes CFI to reject the call, triggering either a kernel panic or killing the calling thread. This only affects systems compiled with Clang's CFI support enabled and running on Texas Instruments NETCP hardware. Without CFI enabled, the incorrect return type is harmless due to ABI compatibility between int and the enum.

Red Hat mitigation

To mitigate this issue, prevent the netcp_core module from being loaded. See https://access.redhat.com/solutions/41278 for instructions on blacklisting kernel modules.

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Oct 4, 2025
Updated May 11, 2026
Reserved Oct 4, 2025

CISA Vulnrichment

No data

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Oct 4, 2025
Bugzilla 2401477

ENISA EUVD

Assigner Linux
Published Oct 4, 2025
Updated May 11, 2026

GitHub

No data