Medium severity5.5NVD Advisory· Published Jun 25, 2026· Updated Jul 6, 2026
CVE-2026-53177
CVE-2026-53177
Description
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Fix NULL pointer dereference
PCIe errors detected by a Root Port or Downstream Port cause error recovery services to run on all subordinate devices regardless of administrative state.
The .error_detected() callback, bnxt_io_error_detected(), disables and synchronizes IRQs via bnxt_disable_int_sync(), which calls bnxt_cp_num_to_irq_num() to map completion rings to IRQs using bp->bnapi.
Since bp->bnapi is allocated on NIC open and freed on NIC close, PCIe error recovery on a closed NIC can dereference a NULL pointer.
Check if bp->bnapi is NULL before disabling and synchronizing IRQs.
Affected products
21cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=4.17,<5.15.210
- cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*
- (no CPE)
- osv-coords12 versionspkg:apk/chainguard/linux-aws-6.12pkg:apk/chainguard/linux-aws-6.18pkg:apk/chainguard/linux-azure-6.18pkg:apk/chainguard/linux-gcp-6.18pkg:apk/chainguard/linux-gcp-6.18-bootc-boot-installedpkg:apk/chainguard/linux-qemu-6.12pkg:apk/chainguard/linux-qemu-6.18pkg:apk/chainguard/linux-qemu-6.18-bootc-boot-installedpkg:apk/chainguard/linux-qemu-melangepkg:apk/chainguard/linux-vmware-6.12pkg:apk/chainguard/linux-vmware-6.18pkg:linux/kernel
< 6.12.95-r0+ 11 more
- (no CPE)range: < 6.12.95-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.12.95-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.12.95-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: >= 4.17.0, < 5.10.260
Patches
Vulnerability mechanics
References
8- git.kernel.org/stable/c/08e57d014ea19f303d5d57a849beb846f37788b7nvdPatch
- git.kernel.org/stable/c/1449177b87f768353909e930a99b902675119b2bnvdPatch
- git.kernel.org/stable/c/1a418ad0e5e525d1d117dd1601681f75455af320nvdPatch
- git.kernel.org/stable/c/3884976f87448e269908ae61bd5d62d54ce9c0c7nvdPatch
- git.kernel.org/stable/c/580844a9683afe7974856dd5b7886447435b3474nvdPatch
- git.kernel.org/stable/c/59c5a3e69c7630a811565937e64be70b08436761nvdPatch
- git.kernel.org/stable/c/964b1c3eb71afe58bb61c8b984164447e000ae8anvdPatch
- git.kernel.org/stable/c/d930276f2cddd0b7294cac7a8fe7b877f6d9e08dnvdPatch
News mentions
1- Linux Kernel: 25 CVEs Land in a Single Day, Spanning Bluetooth to Memory ManagementVypr Intelligence · Jun 26, 2026