cbcvebase.
CVE-2026-53088
published 2026-06-24

CVE-2026-53088: In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb The write_ptr points to the next open…

PriorityP343critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.40%
32.5th percentile
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb The write_ptr points to the next open tx_cb. We want to return the tx_cb that gets rewinded, so we must rewind the pointer first then return the tx_cb that it points to. That way the txcb can be correctly cleaned up.

Affected

12 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux
linuxlinux>= 3.16.50 < 3.173.17
linuxlinux>= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 14e9f86564fff7bcf7f45c1b69080e837b31d18514e9f86564fff7bcf7f45c1b69080e837b31d185
linuxlinux>= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < fb9a3c1f547d0ff024dbfe7b6f327626ddf0a3defb9a3c1f547d0ff024dbfe7b6f327626ddf0a3de
linuxlinux>= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 85f34ec320d3881badfd4edc5fee5cd5012bb54d85f34ec320d3881badfd4edc5fee5cd5012bb54d
linuxlinux>= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 2a74590170427a3ca7cc4bb8690cdd559129c29c2a74590170427a3ca7cc4bb8690cdd559129c29c
linuxlinux>= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 29394f722f620281f2ee9a47f947734e53d72c9029394f722f620281f2ee9a47f947734e53d72c90
linuxlinux>= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 4cab761fc51c65aef741fcece4a18f3554edbc094cab761fc51c65aef741fcece4a18f3554edbc09
linuxlinux>= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 72df896e31ddd06fcc5a789f025ad7a62a18bc9b72df896e31ddd06fcc5a789f025ad7a62a18bc9b
linuxlinux>= 876dbadd53a7102e2a84afc84ea2bd3ee6dc5636 < 57f3f53d2c9c5a9e133596e2f7bc1c50688a6d3857f3f53d2c9c5a9e133596e2f7bc1c50688a6d38
linuxlinux_kernel

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.