CVE-2025-71092

HIGH

Linux Kernel 6.18-6.18.3 - Out-of-bounds Write in bnxt_re_copy_err_stats

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix OOB write in bnxt_re_copy_err_stats() Commit ef56081d1864 ("RDMA/bnxt_re: RoCE related hardware counters update") added three new counters and placed them after BNXT_RE_OUT_OF_SEQ_ERR. BNXT_RE_OUT_OF_SEQ_ERR acts as a boundary marker for allocating hardware statistics with different num_counters values on chip_gen_p5_p7 devices. As a result, BNXT_RE_NUM_STD_COUNTERS are used when allocating hw_stats, which leads to an out-of-bounds write in bnxt_re_copy_err_stats(). The counters BNXT_RE_REQ_CQE_ERROR, BNXT_RE_RESP_CQE_ERROR, and BNXT_RE_RESP_REMOTE_ACCESS_ERRS are applicable to generic hardware, not only p5/p7 devices. Fix this by moving these counters before BNXT_RE_OUT_OF_SEQ_ERR so they are included in the generic counter set.

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 7.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (10)
linux/Kernel 6.18.0 - 6.18.4linux
Linux/Linux < 6.18
Linux/Linux 6.18
Linux/Linux 6.18.4 - 6.18.*
Linux/Linux 6.19
Linux/Linux ef56081d1864582a6db50710733416c0510b7826 - 369a161c48723f60f06f3510b82ea7d96d0499ab
Linux/Linux ef56081d1864582a6db50710733416c0510b7826 - 9b68a1cc966bc947d00e4c0df7722d118125aa37
linux/linux_kernel 6.18
linux/linux_kernel 6.19 rc1 (8 CPE variants)
linux/linux_kernel 6.18.1 - 6.18.4
Published Jan 13, 2026
Tracked Since Feb 18, 2026