CVE-2026-43034

MEDIUM

bnxt_en: set backing store type from query type

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: set backing store type from query type bnxt_hwrm_func_backing_store_qcaps_v2() stores resp->type from the firmware response in ctxm->type and later uses that value to index fixed backing-store metadata arrays such as ctx_arr[] and bnxt_bstore_to_trace[]. ctxm->type is fixed by the current backing-store query type and matches the array index of ctx->ctx_arr. Set ctxm->type from the current loop variable instead of depending on resp->type. Also update the loop to advance type from next_valid_type in the for statement, which keeps the control flow simpler for non-valid and unchanged entries.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 2.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (10)
Linux/Linux < 6.8
Linux/Linux 6.18.22 - 6.18.*
Linux/Linux 6.19.12 - 6.19.*
Linux/Linux 6.8
Linux/Linux 6a4d0774f02d61f8c75ffe2e38a8553410fe52e9 - 29732b68a6816a815d58e9ab229844c23617e1e0
Linux/Linux 6a4d0774f02d61f8c75ffe2e38a8553410fe52e9 - 4ee937107d52f9e5c350e4b5e629760e328b3d9f
Linux/Linux 6a4d0774f02d61f8c75ffe2e38a8553410fe52e9 - c8d53b70166d1dc463ef42adb7293e1a770822c7
Linux/Linux 7.0
linux/linux_kernel 7.0 rc1 (6 CPE variants)
linux/linux_kernel 6.8 - 6.18.22
Published May 01, 2026
Tracked Since May 01, 2026