Database/Firmware, BMC & network fabric
Linux bnxt_en driver (XDP redirect list flush): List corruption in the XDP redirect path, found crashing production
Impact
List corruption in the XDP redirect path, found crashing production systems. Same family as the other bnxt XDP defects: if you run XDP for packet steering in front of inference endpoints, the Broadcom driver's redirect path has repeatedly been the weak spot, and the failure mode is a host crash rather than a graceful drop.
Who can reach it
Traffic through an attached XDP program using redirect on a Broadcom NIC.
What to do
Kernel/driver upgrade plus host reboot. Companion fix CVE-2025-38439 (wrong DMA unmap length on XDP_REDIRECT) is in the same area — take both. Interim: detach XDP from Broadcom interfaces.
References
Related entries
- Linux kernel NVMe-oF TCP host (nvme-tcp R2T PDU request-list handling): Nvme_tcp_handle_r2t() did not check that theCVE-2025-38264 · Linux kernel NVMe-oF TCP host (nvme-tcp R2T PDU request-list handling)Critical
- Ampere AmpereOne AC03 before 3.5.9.3, AC04 before 4.4.5.2, AmpereOne M before 5.4.5.1CVE-2025-62863 · Ampere AmpereOne AC03 before 3.5.9.3, AC04 before 4.4.5.2, AmpereOne M before 5.4.5.1 - UEFI Management Mode PCIe…Critical
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): The inline copy path adds a page index where itCVE-2025-68811 · Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range)Critical
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): svc_rdma_copy_inline_range indexes rq_pages with anCVE-2025-71068 · Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range)Critical
- Linux RDMA/srpt: failed multi-buffer descriptor setup leaves stale counters and a dangling rw_ctxs pointerCVE-2026-100075 · Linux kernel RDMA/srpt (SRP target, srpt_alloc_rw_ctxs unwind)Critical
- Cisco Nexus 9000: unauthenticated remote code execution as root via Silicon One ports in the default L3 VRFCVE-2026-20212 · Cisco Nexus 9000 NX-OS Silicon One integration (S1HAL, TCP 43210/43211)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.