CVE-2026-31395 — Out-of-bounds Write in Linux
Severity
6.3MEDIUM
No vectorEPSS
0.0%
top 94.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 3
Description
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler
The ASYNC_EVENT_CMPL_EVENT_ID_DBG_BUF_PRODUCER handler in
bnxt_async_event_process() uses a firmware-supplied 'type' field
directly as an index into bp->bs_trace[] without bounds validation.
The 'type' field is a 16-bit value extracted from DMA-mapped completion
ring memory that the NIC writes directly to host RAM. A malicious or
compromised NIC can supply any va…
Affected Packages3 packages
▶CVEListV5linux/linux84fcd9449fd7882ddfb05ba64d75f9be2d29b2e9 — 19aa416eed9e4aaf1bbe8da0f7bd9a9be31158c8+3
🔴Vulnerability Details
2OSV▶
CVE-2026-31395: In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler The ASYNC_EVENT_CM↗2026-04-03
GHSA▶
GHSA-prjx-7cfw-rqr7: In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler
The ASYNC_EVENT_↗2026-04-03
📋Vendor Advisories
2🕵️Threat Intelligence
1💬Community
1Bugzilla
▶