In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix...
zetlyn/cve-ghsa vulnerability ghsa GHSA-5g7r-gvc6-8wjf cve CVE-2026-98051 known 2026-09-25
https://github.com/advisories/GHSA-5g7r-gvc6-8wjf
Properties
| severity | unknownreceipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-98051",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [],
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bcmasp: fix tx_spb_ring_full() checking same slot cnt times\n\nThe loop initialised next_index from intf->tx_spb_index on every\niteration, so incr_ring() always produced the same result and only\none slot was ever tested. Move the initialisation before the loop\nso each iteration advances next_index and the function correctly\nchecks that cnt consecutive descriptor slots are available before\nallowing a new transmission.",
"epss": {
"percentage": 0.00168,
"percentile": 0.05413
},
"ghsa_id": "GHSA-5g7r-gvc6-8wjf",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-5g7r-gvc6-8wjf",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-5g7r-gvc6-8wjf"
},
{
"type": "CVE",
"value": "CVE-2026-98051"
}
],
"nvd_published_at": "2026-09-25T11:17:34Z",
"published_at": "2026-09-25T12:31:34Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-98051",
"https://git.kernel.org/stable/c/0c5cf62e72d7a666ee4da757e122dc1600df1ecc",
"https://git.kernel.org/stable/c/5df7ecd302488287665ab9767bacba7ed7e2842f",
"https://git.kernel.org/stable/c/a8bddab54aa68b407f12294acb05bd552fb6a492",
"https://git.kernel.org/stable/c/f7f7a16dd46ace4e221336a184c7806f7de19547",
"https://github.com/advisories/GHSA-5g7r-gvc6-8wjf"
],
"repository_advisory_url": null,
"severity": "unknown",
"source_code_location": "",
"summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bcmasp: fix...",
"type": "unreviewed",
"updated_at": "2026-09-25T12:31:46Z",
"url": "https://api.github.com/advisories/GHSA-5g7r-gvc6-8wjf",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|
Text
In the Linux kernel, the following vulnerability has been resolved:
net: bcmasp: fix...
In the Linux kernel, the following vulnerability has been resolved:
net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times
The loop initialised next_index from intf->tx_spb_index on every
iteration, so incr_ring() always produced the same result and only
one slot was ever tested. Move the initialisation before the loop
so each iteration advances next_index and the function correctly
checks that cnt consecutive descriptor slots are available before
allowing a new transmission.