CVE-2026-53086
Critical · CVSS 9.8Linux Kernel bcmgenet — Race condition / timeout handler queue management
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-362
Description
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmgenet_timeout handler tries to take down all tx queues when a single queue times out. This is over zealous and causes many race conditions with queues that are still chugging along. Instead lets only restart the timed out queue.
Search profile — drives PoC discovery
Symbols bcmgenet_timeoutbcmgenet_tx_timeoutnetif_tx_stop_all_queuesnetif_tx_wake_queuebcmgenet_tx_ringbcmgenet_umac_resetGENET_TX_RINGbcmgenet_tx_reclaim
Keywords CVE-2026-53086bcmgenet timeout handler race conditionbcmgenet tx queue timeout fixLinux kernel bcmgenet net driver racebcmgenet_timeout racing fixbcmgenet tx queue restart patch
Versions: Linux kernel versions prior to fixes at 5393b2b5bee2, 681fdfe823b4, 7ce1c26aac3b, c270e2bec3e5, e8206538cbaf
Affected packages
| Linux | Kernel | 4.2.0 → 6.1.175 |
| Linux | Kernel | 6.13.0 → 6.18.33 |
| Linux | Kernel | 6.19.0 → 7.0.10 |
| Linux | Kernel | 6.2.0 → 6.6.141 |
| Linux | Kernel | 6.7.0 → 6.12.91 |
References
- https://git.kernel.org/stable/c/5393b2b5bee2ac51a0043dc7f4ac3475f053d08d
- https://git.kernel.org/stable/c/681fdfe823b4f1036ed50b58b8838c7917ea389c
- https://git.kernel.org/stable/c/7ce1c26aac3b318886a57425f64b522da7389153
- https://git.kernel.org/stable/c/c270e2bec3e55a716d25c35341091339457ac883
- https://git.kernel.org/stable/c/e8206538cbaf4f4068e99a4cb1138690a1e00499
- https://git.kernel.org/stable/c/e85b0c0a12e967930044608311471b665baa315c
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z