Data Corruption Vulnerability in Linux Kernel Affects Broadcom BNXT Ethernet Driver
CVE-2026-74697
What is CVE-2026-74697?
The BNXT Ethernet Driver in the Linux kernel contains a vulnerability that can lead to data corruption due to improper handling of End of Frame Padding (EOP) on AGG rings. Specifically, on older chips (P5 and earlier), the system's Relaxed Ordering (RO) feature can unintentionally overwrite valid data with zero padding from the previous segment. This occurs when EOP is enabled while TPA (TCP Segmentation Offload) is active. The recommended fix is to disable EOP across all chips on AGG rings to prevent potential data integrity issues.
Affected Version(s)
Linux bfcd8d791ec18496772d117774398e336917f56e < 68c181af7cd1ca9cbf29acd95911073bfd3c6397
Linux bfcd8d791ec18496772d117774398e336917f56e < 7aee22a35978b44784612c156e358e375ddf5d16
Linux bfcd8d791ec18496772d117774398e336917f56e < 410da4428b1f47bf9a84bdc0bcaa089d73ba2048