{"api_version":"1","generated_at":"2026-09-20T21:39:45+00:00","cve":"CVE-2026-80998","urls":{"html":"https://cve.report/CVE-2026-80998","api":"https://cve.report/api/cve/CVE-2026-80998.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80998","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80998"},"summary":{"title":"net: bnxt: ring the doorbell when SW USO exits early","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bnxt: ring the doorbell when SW USO exits early\n\nWhen a burst of packets is handed down to the driver, the driver defers\nthe doorbell to the end by setting txr->kick_pending = 1. The normal TX\npath handles this, but the SW USO path can miss it if it returns\nearly.\n\nIf bnxt_sw_udp_gso_xmit runs but returns early with NETDEV_TX_BUSY and\ntxr->kick_pending was previously set to 1, then the TX queue can\nstall because the driver wrote some BDs but never wrote the doorbell.\nThe device won't know to do the TX which would generate the completion\nthat would wake the queue back up.\n\nSimplify bnxt_sw_udp_gso_xmit to set txr->kick_pending in its success\ncase and check the flag on return. The added check after\nbnxt_sw_udp_gso_xmit returns ensures that any pending doorbells are\nwritten handling both successful USO and any early returns, which\nprevents the TX queue stall mentioned above.\n\nThis TX queue stall was observed on a production system with a netdev TX\nwatchdog informing about the queue stall.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-11 20:19:06","updated_at":"2026-09-13 07:17:06"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/48d1c9665db6e3d4aeca62eb669377162ebc6fdf","name":"https://git.kernel.org/stable/c/48d1c9665db6e3d4aeca62eb669377162ebc6fdf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4e15e89faac9f308baeb01f46c13a051814d2449","name":"https://git.kernel.org/stable/c/4e15e89faac9f308baeb01f46c13a051814d2449","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80998","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80998","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cc5d90667db81474ed7a92a1b2fa3daec5559307 48d1c9665db6e3d4aeca62eb669377162ebc6fdf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cc5d90667db81474ed7a92a1b2fa3daec5559307 4e15e89faac9f308baeb01f46c13a051814d2449 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.1","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.4 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"80998","cve":"CVE-2026-80998","epss":"0.004670000","percentile":"0.391300000","score_date":"2026-09-14","updated_at":"2026-09-15 00:00:42"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/ethernet/broadcom/bnxt/bnxt.c","drivers/net/ethernet/broadcom/bnxt/bnxt_gso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"48d1c9665db6e3d4aeca62eb669377162ebc6fdf","status":"affected","version":"cc5d90667db81474ed7a92a1b2fa3daec5559307","versionType":"git"},{"lessThan":"4e15e89faac9f308baeb01f46c13a051814d2449","status":"affected","version":"cc5d90667db81474ed7a92a1b2fa3daec5559307","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/ethernet/broadcom/bnxt/bnxt.c","drivers/net/ethernet/broadcom/bnxt/bnxt_gso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.1"},{"lessThan":"7.1","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.4","versionStartIncluding":"7.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"7.1","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bnxt: ring the doorbell when SW USO exits early\n\nWhen a burst of packets is handed down to the driver, the driver defers\nthe doorbell to the end by setting txr->kick_pending = 1. The normal TX\npath handles this, but the SW USO path can miss it if it returns\nearly.\n\nIf bnxt_sw_udp_gso_xmit runs but returns early with NETDEV_TX_BUSY and\ntxr->kick_pending was previously set to 1, then the TX queue can\nstall because the driver wrote some BDs but never wrote the doorbell.\nThe device won't know to do the TX which would generate the completion\nthat would wake the queue back up.\n\nSimplify bnxt_sw_udp_gso_xmit to set txr->kick_pending in its success\ncase and check the flag on return. The added check after\nbnxt_sw_udp_gso_xmit returns ensures that any pending doorbells are\nwritten handling both successful USO and any early returns, which\nprevents the TX queue stall mentioned above.\n\nThis TX queue stall was observed on a production system with a netdev TX\nwatchdog informing about the queue stall."}],"metrics":[{"cvssV3_1":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - The flaw is in bnxt_start_xmit (ndo_start_xmit) on Broadcom NetXtreme NICs; a remote attacker can induce software UDP GSO egress via QUIC/HTTP3 replies, forwarded or bridged tenant flows, or hypervisor uplink transmit on internet-facing cloud and datacenter servers without local shell access.\nAC:L - An attacker can drive a TX burst that sets kick_pending and then a UDP GSO skb that returns NETDEV_TX_BUSY by flooding mixed-size UDP/GSO traffic until the ring or inline header slots are full; this is a deterministic missed-doorbell logic bug, not a race or layout condition outside attacker control.\nPR:N - Reaching bnxt_sw_udp_gso_xmit requires only the ability to cause UDP GSO packets to egress an already-up bnxt interface; unauthenticated QUIC/UDP service traffic and forwarded packets hit this path with no local account, capability, or CAP_NET_ADMIN.\nUI:N - Exploitation needs only attacker-generated network traffic that produces UDP GSO transmit on a live bnxt uplink; no victim action such as mounting a filesystem or opening a file is required.\nS:U - The missed doorbell stalls and resets transmit queues inside the same kernel/netdev authority and does not cross a VM, IOMMU, or sandbox security boundary.\nC:N - The defect only skips a TX doorbell write after an early NETDEV_TX_BUSY or drop return from software USO; it does not read packet or kernel memory and yields no information-disclosure primitive.\nI:N - No buffer overflow, use-after-free, or other memory corruption occurs; previously posted buffer descriptors are simply never kicked, so there is no unauthorized modification or control-flow hijack.\nA:H - Skipping the doorbell leaves posted TX descriptors unprocessed so completions never arrive, the queue stays stopped, and the netdev watchdog calls bnxt_tx_timeout() and bnxt_reset_task(); repeating the pattern sustains a complete loss of connectivity on the affected NIC."}]}],"providerMetadata":{"dateUpdated":"2026-09-13T06:29:01.300Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/48d1c9665db6e3d4aeca62eb669377162ebc6fdf"},{"url":"https://git.kernel.org/stable/c/4e15e89faac9f308baeb01f46c13a051814d2449"}],"title":"net: bnxt: ring the doorbell when SW USO exits early","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80998","datePublished":"2026-09-11T19:42:52.861Z","dateReserved":"2026-08-26T14:34:25.812Z","dateUpdated":"2026-09-13T06:29:01.300Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-11 20:19:06","lastModifiedDate":"2026-09-13 07:17:06","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80998","Ordinal":"1","Title":"net: bnxt: ring the doorbell when SW USO exits early","CVE":"CVE-2026-80998","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80998","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bnxt: ring the doorbell when SW USO exits early\n\nWhen a burst of packets is handed down to the driver, the driver defers\nthe doorbell to the end by setting txr->kick_pending = 1. The normal TX\npath handles this, but the SW USO path can miss it if it returns\nearly.\n\nIf bnxt_sw_udp_gso_xmit runs but returns early with NETDEV_TX_BUSY and\ntxr->kick_pending was previously set to 1, then the TX queue can\nstall because the driver wrote some BDs but never wrote the doorbell.\nThe device won't know to do the TX which would generate the completion\nthat would wake the queue back up.\n\nSimplify bnxt_sw_udp_gso_xmit to set txr->kick_pending in its success\ncase and check the flag on return. The added check after\nbnxt_sw_udp_gso_xmit returns ensures that any pending doorbells are\nwritten handling both successful USO and any early returns, which\nprevents the TX queue stall mentioned above.\n\nThis TX queue stall was observed on a production system with a netdev TX\nwatchdog informing about the queue stall.","Type":"Description","Title":"net: bnxt: ring the doorbell when SW USO exits early"}]}}}