OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-98052

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's bcmasp driver, where the `txcb->last` field may retain a stale value from previous transmissions, leading to premature freeing of sk_buff structures during packet transmission. This can result in data corruption or loss as remaining fragments are improperly handled. Organizations utilizing Linux systems with the bcmasp driver should prioritize addressing this issue to ensure the integrity and reliability of their network communications.

CVE
CVE-2026-98052
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: clear txcb->last before writing each descriptor bcmasp_xmit() only wrote txcb->last = true for the final fragment of an SKB; non-final fragments left the field untouched. If a descriptor slot was reused while it still held a stale true from a previous SKB (possible when tx_spb_ring_full() underreported fullness), bcmasp_tx_reclaim() would see last == true mid-SKB and call dev_consume_skb_any() prematurely, freeing the sk_buff while its remaining fragments were still in flight. Unconditionally clear txcb->last before the conditional set so every descriptor slot starts from a known false state regardless of what a prior transmission left behind.

Related CVEs

Other vulnerabilities affecting the same vendor(s)