CVE-2026-98051 — In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times The loop ini…
Description
In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times The loop initialised next_index from intf->tx_spb_index on every iteration, so incr_ring() always produced the same result and only one slot was ever tested. Move the initialisation before the loop so each iteration advances next_index and the function correctly checks that cnt consecutive descriptor slots are available before allowing a new transmission.
CVSS v3.1 base metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
Low
Attack Complexity
PR
Low
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
None
Confidentiality
I
None
Integrity
A
High
Availability
Affected
- Vendor
- linux
- Product
- linux kernel
Versions
- >= 6.6, < 6.6.158
- >= 6.7, < 6.12.111
- >= 6.13, < 6.18.53
- >= 6.19, < 7.2.7
- 7.3
Stated as the source expressed them.
References
- patchPatchhttps://git.kernel.org/stable/c/0c5cf62e72d7a666ee4da757e122dc1600df1ecc
- patchPatchhttps://git.kernel.org/stable/c/5df7ecd302488287665ab9767bacba7ed7e2842f
- patchPatchhttps://git.kernel.org/stable/c/a8bddab54aa68b407f12294acb05bd552fb6a492
- patchPatchhttps://git.kernel.org/stable/c/f7f7a16dd46ace4e221336a184c7806f7de19547
- patchPatchhttps://git.kernel.org/stable/c/990df1ba4d0805d1e7f6148c364febd2ab618766
Related threats
same CWE or vendorCVE-2026-107284 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.
CVE-2026-107284 · 1d ago
CVE-2026-106586 — In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a differe…
CVE-2026-106586 · 2d ago
CVE-2026-102124 — A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration.
CVE-2026-102124 · 8d ago
CVE-2026-102110 — An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so du…
CVE-2026-102110 · 8d ago
CVE-2026-98164 — In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tra…
CVE-2026-98164 · 10d ago
CVE-2026-96760 — Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability.
CVE-2026-96760 · 10d ago