Back

HIGH

bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler

Published Apr 3, 2026

Description

The ASYNC_EVENT_CMPL_EVENT_ID_DBG_BUF_PRODUCER handler in bnxt_async_event_process() uses a firmware-supplied 'type' field directly as an index into bp->bs_trace[] without bounds validation.

The 'type' field is a 16-bit value extracted from DMA-mapped completion ring memory that the NIC writes directly to host RAM. A malicious or compromised NIC can supply any value from 0 to 65535, causing an out-of-bounds access into kernel heap memory.

The bnxt_bs_trace_check_wrap() call then dereferences bs_trace->magic_byte and writes to bs_trace->last_offset and bs_trace->wrapped, leading to kernel memory corruption or a crash.

Fix by adding a bounds check and defining BNXT_TRACE_MAX as DBG_LOG_BUFFER_FLUSH_REQ_TYPE_ERR_QPC_TRACE + 1 to cover all currently defined firmware trace types (0x0 through 0xc).

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Apr 3, 2026
Updated May 11, 2026
Reserved Mar 9, 2026

CISA Vulnrichment

No data

NVD

Status Analyzed
Modified Jul 24, 2026

Red Hat

Severity Moderate
Public date Apr 3, 2026
Bugzilla 2454872

ENISA EUVD

Assigner Linux
Published Apr 3, 2026
Updated May 11, 2026

GitHub

No data