CVE-2026-43260
published 2026-05-06CVE-2026-43260: In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix RSS context delete logic We need to free the corresponding RSS context VNIC in…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Fix RSS context delete logic
We need to free the corresponding RSS context VNIC
in FW everytime an RSS context is deleted in driver.
Commit 667ac333dbb7 added a check to delete the VNIC
in FW only when netif_running() is true to help delete
RSS contexts with interface down.
Having that condition will make the driver leak VNICs
in FW whenever close() happens with active RSS contexts.
On the subsequent open(), as part of RSS context restoration,
we will end up trying to create extra VNICs for which we
did not make any reservation. FW can fail this request,
thereby making us lose active RSS contexts.
Suppose an RSS context is deleted already and we try to
process a delete request again, then the HWRM functions
will check for validity of the request and they simply
return if the resource is already freed. So, even for
delete-when-down cases, netif_running() check is not
necessary.
Remove the netif_running() condition check when deleting
an RSS context.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 667ac333dbb7e265b3f5bc4bc94e236f64682c86 < 348a5f8d06c7bdf954e13c17ad5f80b59a075604 | 348a5f8d06c7bdf954e13c17ad5f80b59a075604 |
| linux | linux | >= 667ac333dbb7e265b3f5bc4bc94e236f64682c86 < 079986d6db1f8e3d50c55f400cf998ac9690d2c8 | 079986d6db1f8e3d50c55f400cf998ac9690d2c8 |
| linux | linux | >= 667ac333dbb7e265b3f5bc4bc94e236f64682c86 < 9a9b89eea4a9cc7726702946ff688d716962fabd | 9a9b89eea4a9cc7726702946ff688d716962fabd |
| linux | linux | >= 667ac333dbb7e265b3f5bc4bc94e236f64682c86 < e123d9302d223767bd910bfbcfe607bae909f8ac | e123d9302d223767bd910bfbcfe607bae909f8ac |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 6.11 < 6.12.75 | 6.12.75 |
| linux | linux_kernel | >= 6.13 < 6.18.16 | 6.18.16 |
| linux | linux_kernel | >= 6.19 < 6.19.6 | 6.19.6 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: bnxt_en: Fix RSS context delete logic
vendor_redhat·2026-05-06·CVSS 5.5
CVE-2026-43260 [MEDIUM] CWE-772 kernel: bnxt_en: Fix RSS context delete logic
kernel: bnxt_en: Fix RSS context delete logic
A flaw was found in the bnxt_en driver of the Linux kernel. An issue in the RSS (Receive Side Scaling) context deletion logic can lead to a leak of VNICs (Virtual Network Interface Controllers) in the firmware. This can cause subsequent attempts to create new VNICs to fail, resulting in the loss of active RSS contexts. This vulnerability could lead to a Denial of Service (DoS) for network operations.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise
GHSA
GHSA-w6jm-j85g-vpgj: In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Fix RSS context delete logic
We need to free the corresponding RSS cont
ghsa_unreviewed·2026-05-06
CVE-2026-43260 GHSA-w6jm-j85g-vpgj: In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Fix RSS context delete logic
We need to free the corresponding RSS cont
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Fix RSS context delete logic
We need to free the corresponding RSS context VNIC
in FW everytime an RSS context is deleted in driver.
Commit 667ac333dbb7 added a check to delete the VNIC
in FW only when netif_running() is true to help delete
RSS contexts with interface down.
Having that condition will make the driver leak VNICs
in FW whenever close() happens with active RSS contexts.
On the subsequent open(), as part of RSS context restoration,
we will end up trying to create extra VNICs for which we
did not make any reservation. FW can fail this request,
thereby making us lose active RSS contexts.
Suppose an RSS context is deleted already and we try to
process a delete request again, then the HWRM functions
wi
No detection rules found.
No public exploits indexed.
2026-05-06
Published