bnxt_en: Fix NULL pointer dereference

Summary

CVECVE-2026-53177
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-06-25 09:16:35 UTC
Updated2026-06-25 09:16:35 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix NULL pointer dereference PCIe errors detected by a Root Port or Downstream Port cause error recovery services to run on all subordinate devices regardless of administrative state. The .error_detected() callback, bnxt_io_error_detected(), disables and synchronizes IRQs via bnxt_disable_int_sync(), which calls bnxt_cp_num_to_irq_num() to map completion rings to IRQs using bp->bnapi. Since bp->bnapi is allocated on NIC open and freed on NIC close, PCIe error recovery on a closed NIC can dereference a NULL pointer. Check if bp->bnapi is NULL before disabling and synchronizing IRQs.

Risk And Classification

EPSS: 0.001720000 probability, percentile 0.068650000 (date 2026-06-25)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected e5811b8c09df9bc80eabc95339fceded23f16289 964b1c3eb71afe58bb61c8b984164447e000ae8a git Not specified
CNA Linux Linux affected e5811b8c09df9bc80eabc95339fceded23f16289 59c5a3e69c7630a811565937e64be70b08436761 git Not specified
CNA Linux Linux affected e5811b8c09df9bc80eabc95339fceded23f16289 1a418ad0e5e525d1d117dd1601681f75455af320 git Not specified
CNA Linux Linux affected e5811b8c09df9bc80eabc95339fceded23f16289 08e57d014ea19f303d5d57a849beb846f37788b7 git Not specified
CNA Linux Linux affected e5811b8c09df9bc80eabc95339fceded23f16289 3884976f87448e269908ae61bd5d62d54ce9c0c7 git Not specified
CNA Linux Linux affected e5811b8c09df9bc80eabc95339fceded23f16289 580844a9683afe7974856dd5b7886447435b3474 git Not specified
CNA Linux Linux affected e5811b8c09df9bc80eabc95339fceded23f16289 d930276f2cddd0b7294cac7a8fe7b877f6d9e08d git Not specified
CNA Linux Linux affected 4.17 Not specified
CNA Linux Linux unaffected 4.17 semver Not specified
CNA Linux Linux unaffected 5.15.210 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.176 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.143 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.94 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.36 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.13 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/3884976f87448e269908ae61bd5d62d54ce9c0c7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/964b1c3eb71afe58bb61c8b984164447e000ae8a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/08e57d014ea19f303d5d57a849beb846f37788b7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/580844a9683afe7974856dd5b7886447435b3474 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d930276f2cddd0b7294cac7a8fe7b877f6d9e08d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1a418ad0e5e525d1d117dd1601681f75455af320 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/59c5a3e69c7630a811565937e64be70b08436761 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report