CVE-2026-53088
published 2026-06-24CVE-2026-53088: In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb The write_ptr points to the next open…
PriorityP343critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.40%
32.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
The write_ptr points to the next open tx_cb. We want to return the
tx_cb that gets rewinded, so we must rewind the pointer first then
return the tx_cb that it points to. That way the txcb can be correctly
cleaned up.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 3.16.50 < 3.17 | 3.17 |
| linux | linux | >= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 14e9f86564fff7bcf7f45c1b69080e837b31d185 | 14e9f86564fff7bcf7f45c1b69080e837b31d185 |
| linux | linux | >= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < fb9a3c1f547d0ff024dbfe7b6f327626ddf0a3de | fb9a3c1f547d0ff024dbfe7b6f327626ddf0a3de |
| linux | linux | >= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 85f34ec320d3881badfd4edc5fee5cd5012bb54d | 85f34ec320d3881badfd4edc5fee5cd5012bb54d |
| linux | linux | >= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 2a74590170427a3ca7cc4bb8690cdd559129c29c | 2a74590170427a3ca7cc4bb8690cdd559129c29c |
| linux | linux | >= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 29394f722f620281f2ee9a47f947734e53d72c90 | 29394f722f620281f2ee9a47f947734e53d72c90 |
| linux | linux | >= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 4cab761fc51c65aef741fcece4a18f3554edbc09 | 4cab761fc51c65aef741fcece4a18f3554edbc09 |
| linux | linux | >= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 72df896e31ddd06fcc5a789f025ad7a62a18bc9b | 72df896e31ddd06fcc5a789f025ad7a62a18bc9b |
| linux | linux | >= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 57f3f53d2c9c5a9e133596e2f7bc1c50688a6d38 | 57f3f53d2c9c5a9e133596e2f7bc1c50688a6d38 |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
vendor_redhat·2026-06-24·CVSS 5.5
CVE-2026-53088 [LOW] CWE-193 kernel: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
kernel: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
A flaw was found in the Linux kernel's bcmgenet network driver. An off-by-one error in the `bcmgenet_put_txcb` function, related to the `write_ptr` handling for transmit control blocks (tx_cb), could lead to incorrect cleanup of these blocks. This issue may result in system instability or unexpected behavior.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Fix defe
GHSA
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb The write_ptr points to the next open tx_cb.
ghsa_unreviewed·2026-06-24
CVE-2026-53088 In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb The write_ptr points to the next open tx_cb.
In the Linux kernel, the following vulnerability has been resolved:
net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
The write_ptr points to the next open tx_cb. We want to return the
tx_cb that gets rewinded, so we must rewind the pointer first then
return the tx_cb that it points to. That way the txcb can be correctly
cleaned up.
VulDB
Linux Kernel up to 7.0.9 net off-by-one
vuldb·2026-06-24
CVE-2026-53088 [CRITICAL] Linux Kernel up to 7.0.9 net off-by-one
A vulnerability labeled as critical has been found in Linux Kernel up to 7.0.9. The impacted element is an unknown function of the component net. The manipulation results in off-by-one.
This vulnerability is identified as CVE-2026-53088. The attack can only be performed from the local network. There is not any exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/14e9f86564fff7bcf7f45c1b69080e837b31d185https://git.kernel.org/stable/c/29394f722f620281f2ee9a47f947734e53d72c90https://git.kernel.org/stable/c/2a74590170427a3ca7cc4bb8690cdd559129c29chttps://git.kernel.org/stable/c/4cab761fc51c65aef741fcece4a18f3554edbc09https://git.kernel.org/stable/c/57f3f53d2c9c5a9e133596e2f7bc1c50688a6d38https://git.kernel.org/stable/c/72df896e31ddd06fcc5a789f025ad7a62a18bc9bhttps://git.kernel.org/stable/c/85f34ec320d3881badfd4edc5fee5cd5012bb54dhttps://git.kernel.org/stable/c/fb9a3c1f547d0ff024dbfe7b6f327626ddf0a3de
2026-06-24
Published