Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-74269

In the Linux kernel, the following vulnerability has been resolved: bnxt: fix head underflow on XDP head-grow The xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on a bnxt machine ...
Back to all
CVE

DEBIAN-CVE-2026-74269

In the Linux kernel, the following vulnerability has been resolved: bnxt: fix head underflow on XDP head-grow The xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on a bnxt machine ...

In the Linux kernel, the following vulnerability has been resolved:  bnxt: fix head underflow on XDP head-grow  The xdp.py test testxdpnativeadjstheadgrowdata crashes when run on a bnxt machine (and also crashes in NIPA).  It seems that the bug is an underflow in bnxtrxmultipageskb, which builds the skb head:    napibuildskb(dataptr - bp->rxoffset, rxr->rxpagesize);  The problem with this expression is that in page mode, rxoffset is:    bp->rxoffset = NETIPALIGN + XDPPACKETHEADROOM;  Which evaluates (at least on x8664) to 258.  The test testxdpnativeadjstheadgrowdata tests a case where the head is adjusted by -256.  When this test runs, dataptr is shifted to fragstart + 2 (where fragstart = pageaddress(page) + offset).  Then, bnxtrxmultipageskb is invoked and the napibuildskb expression subtracts 258, landing at an address before fragstart. This could be either the previous fragment or the previous physical page when the offset is < 256 (e.g. if the fragment started at offset 0).  When the skb is freed, the page pool fragment reference is dropped on either the wrong page or the wrong frag of the right page. In either case, the corrupted reference count can lead to the page being prematurely recycled while still in use. Once (incorrectly) recycled, it can be handed out again and on driver teardown this would result in a double free.  The commit under fixes updated this code to handle the case where the native page size is >= 64k, but it unintentionally broke the head grow case.  To fix this, add an offset field to struct bnxtswrxbd, mirroring the existing offset field in struct bnxtswrxaggbd. Populate it on allocation and preserve it on reuse.  In bnxtrxmultipageskb, use the newly added offset field to compute the fragment start and pass that to napibuildskb. Adjust the layout with skbreserve.  There are two cases, the non-adjustment case and the adjustment case.  In both cases, the skb is built at pageaddress(page) + offset to account for the case where the native page size >= 64K and skbreserve is called with dataptr - (pageaddress(page) + offset). That difference equals bp->rxoffset when dataptr was not moved, or bp->rxoffset + xdpadjust when XDP adjusted the head.  Re-running the failing test with this commit applied causes the test to run successfully to completion.  The other rxskbfunc implementations don't have this issue.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-74269

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
7.1.5-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading