CVE-2026-53215
Description
A flaw was found in the Linux kernel's mvpp2 network driver. This vulnerability occurs due to incorrect handling of receive (RX) buffers, where a buffer is returned to the hardware Buffer Manager (BM) pool after it has been passed to the eXpress Data Path (XDP) or attached to a socket buffer (skb). This allows hardware Direct Memory Access (DMA) operations into memory that is no longer controlled by the RX ring, potentially leading to memory corruption.
Understanding the Weakness (CWE)
Integrity,Availability,Confidentiality
Technical Impact: Modify Memory; DoS: Crash, Exit, or Restart; Execute Unauthorized Code or Commands
This weakness may result in the corruption of memory, and perhaps instructions, possibly leading to a crash. If the corrupted memory can be effectively controlled, it may be possible to execute arbitrary code.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.