CVE-2026-43031
published 2026-05-01CVE-2026-43031: In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets When a TX packet spans…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.43%
34.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets
When a TX packet spans multiple buffer descriptors (scatter-gather),
axienet_free_tx_chain sums the per-BD actual length from descriptor
status into a caller-provided accumulator. That sum is reset on each
NAPI poll. If the BDs for a single packet complete across different
polls, the earlier bytes are lost and never credited to BQL. This
causes BQL to think bytes are permanently in-flight, eventually
stalling the TX queue.
The SKB pointer is stored only on the last BD of a packet. When that
BD completes, use skb->len for the byte count instead of summing
per-BD status lengths. This matches netdev_sent_queue(), which debits
skb->len, and naturally survives across polls because no partial
packet contributes to the accumulator.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= c900e49d58eb32b192b6d200ace4ae3ab89779d4 < 2a0323a913109b52bfc9f5ea7b92a1b249e07d3e | 2a0323a913109b52bfc9f5ea7b92a1b249e07d3e |
| linux | linux | >= c900e49d58eb32b192b6d200ace4ae3ab89779d4 < 3c3a6b9020c01fde7b22e8550105de0b59904f61 | 3c3a6b9020c01fde7b22e8550105de0b59904f61 |
| linux | linux | >= c900e49d58eb32b192b6d200ace4ae3ab89779d4 < d1978d03e86785872871bff9c2623174b10740de | d1978d03e86785872871bff9c2623174b10740de |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 6.15 < 6.18.22 | 6.18.22 |
| linux | linux_kernel | >= 6.19 < 6.19.12 | 6.19.12 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets
vendor_redhat·2026-05-01
CVE-2026-43031 CWE-911 kernel: net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets
kernel: net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets
A flaw was found in the Linux kernel's xilinx axienet network driver. This vulnerability arises from incorrect accounting of Buffer Queue Length (BQL), a mechanism that manages network buffer usage, for transmit (TX) packets that are split across multiple buffer descriptors. If these packet segments complete across different processing cycles, the system miscalculates the transmitted data. This error can cause the TX queue to stall, leading to a Denial of Service (DoS) for network communications.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise
GHSA
GHSA-xpr9-pcwr-h574: In the Linux kernel, the following vulnerability has been resolved:
net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets
When a TX packe
ghsa_unreviewed·2026-05-01
CVE-2026-43031 [HIGH] GHSA-xpr9-pcwr-h574: In the Linux kernel, the following vulnerability has been resolved:
net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets
When a TX packe
In the Linux kernel, the following vulnerability has been resolved:
net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets
When a TX packet spans multiple buffer descriptors (scatter-gather),
axienet_free_tx_chain sums the per-BD actual length from descriptor
status into a caller-provided accumulator. That sum is reset on each
NAPI poll. If the BDs for a single packet complete across different
polls, the earlier bytes are lost and never credited to BQL. This
causes BQL to think bytes are permanently in-flight, eventually
stalling the TX queue.
The SKB pointer is stored only on the last BD of a packet. When that
BD completes, use skb->len for the byte count instead of summing
per-BD status lengths. This matches netdev_sent_queue(), which debits
skb->len, and naturally survives
VulDB
Linux Kernel up to 6.18.21/6.19.11 netdev_sent_queue buffer overflow
vuldb·2026-05-01
CVE-2026-43031 [CRITICAL] Linux Kernel up to 6.18.21/6.19.11 netdev_sent_queue buffer overflow
A vulnerability has been found in Linux Kernel up to 6.18.21/6.19.11 and classified as critical. This impacts the function netdev_sent_queue. Performing a manipulation results in buffer overflow.
This vulnerability is cataloged as CVE-2026-43031. The attack must originate from the local network. There is no exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
2026-05-01
Published