<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 05:15:23 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-26859 — net/bnx2x: Prevent access to a freed page in page_pool</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-26859</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/bnx2x: Prevent access to a freed page in page_pool&lt;/p&gt;
&lt;p&gt;Fix race condition leading to system crash during EEH error handling&lt;/p&gt;
&lt;p&gt;During EEH error recovery, the bnx2x driver&amp;#39;s transmit timeout logic
could cause a race condition when handling reset tasks. The
bnx2x_tx_timeout() schedules reset tasks via bnx2x_sp_rtnl_task(),
which ultimately leads to bnx2x_nic_unload(). In bnx2x_nic_unload()
SGEs are freed using bnx2x_free_rx_sge_range(). However, this could
overlap with the EEH driver&amp;#39;s attempt to reset the device using
bnx2x_io_slot_reset(), which also tries to free SGEs. This race
condition can result in system crashes due to accessing freed memory
locations in bnx2x_free_rx_sge()&lt;/p&gt;
&lt;p&gt;799  static inline void bnx2x_free_rx_sge(struct bnx2x *bp,
800				struct bnx2x_fastpath *fp, u16 index)
801  {
802	struct sw_rx_page *sw_buf = &amp;amp;fp-&amp;gt;rx_page_ring[index];
803     struct page *page = sw_buf-&amp;gt;page;
....
where sw_buf was set to NULL after the call to dma_unmap_page()
by the preceding thread.&lt;/p&gt;
&lt;p&gt;EEH: Beginning: &amp;#39;slot_reset&amp;#39;
    PCI 0011:01:00.0#10000: EEH: Invoking bnx2x-&amp;gt;slot_reset()
    bnx2x: [bnx2x_io_slot_reset:14228(eth1)]IO slot reset initializing...
    bnx2x 0011:01:00.0: enabling device (0140 -&amp;gt; 0142)
    bnx2x: [bnx2x_io_slot_reset:14244(eth1)]IO slot reset --&amp;gt; driver unload
    Kernel attempted to read user page (0) - exploit attempt? (uid: 0)
    BUG: Kernel NULL pointer dereference on read at 0x00000000…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/bnx2x: Prevent access to a freed page in page_pool&lt;/p&gt;
&lt;p&gt;Fix race condition leading to system crash during EEH error handling&lt;/p&gt;
&lt;p&gt;During EEH error recovery, the bnx2x driver&amp;#39;s transmit timeout logic
could cause a race condition when handling reset tasks. The
bnx2x_tx_timeout() schedules reset tasks via bnx2x_sp_rtnl_task(),
which ultimately leads to bnx2x_nic_unload(). In bnx2x_nic_unload()
SGEs are freed using bnx2x_free_rx_sge_range(). However, this could
overlap with the EEH driver&amp;#39;s attempt to reset the device using
bnx2x_io_slot_reset(), which also tries to free SGEs. This race
condition can result in system crashes due to accessing freed memory
locations in bnx2x_free_rx_sge()&lt;/p&gt;
&lt;p&gt;799  static inline void bnx2x_free_rx_sge(struct bnx2x *bp,
800				struct bnx2x_fastpath *fp, u16 index)
801  {
802	struct sw_rx_page *sw_buf = &amp;amp;fp-&amp;gt;rx_page_ring[index];
803     struct page *page = sw_buf-&amp;gt;page;
....
where sw_buf was set to NULL after the call to dma_unmap_page()
by the preceding thread.&lt;/p&gt;
&lt;p&gt;EEH: Beginning: &amp;#39;slot_reset&amp;#39;
    PCI 0011:01:00.0#10000: EEH: Invoking bnx2x-&amp;gt;slot_reset()
    bnx2x: [bnx2x_io_slot_reset:14228(eth1)]IO slot reset initializing...
    bnx2x 0011:01:00.0: enabling device (0140 -&amp;gt; 0142)
    bnx2x: [bnx2x_io_slot_reset:14244(eth1)]IO slot reset --&amp;gt; driver unload
    Kernel attempted to read user page (0) - exploit attempt? (uid: 0)
    BUG: Kernel NULL pointer dereference on read at 0x00000000…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-26859</guid>
    </item>
  </channel>
</rss>
