CVE-2026-74737
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
26/08/2026
Última modificación:
27/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG<br />
<br />
On the packet reception path, the ID of the MAC Port on which the packet<br />
was received, is embedded in the RX DMA Descriptor&#39;s metadata. The ID is<br />
extracted using the helper function cppi5_desc_get_tags_ids() which fills<br />
in the 16-bit Source Tag into the &#39;port_id&#39; variable. However, it is only<br />
the lower 8-bits of the 16-bit Source Tag that represent the MAC Port ID,<br />
while the upper 8-bits are Hardware-Reserved and carry an arbitrary value.<br />
With the existing logic, sporadic kernel crash is observed due to the<br />
subsequent driver code accessing out-of-bound memory because of an invalid<br />
port_id.<br />
<br />
Hence, fix the port_id extraction logic to use only the lower 8-bits of the<br />
Source Tag as the MAC Port ID.
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/14fc40bf28390e0ebee6a072457c36b82c614100
- https://git.kernel.org/stable/c/1c0e35ce761131f82062222779d8574849790892
- https://git.kernel.org/stable/c/36a05d2820077bb3955acb8111e1041d39148037
- https://git.kernel.org/stable/c/46a8e084a159e638ac2728e96980b65d752d65fd
- https://git.kernel.org/stable/c/551688b410d3fb0dae7739724422f268cd9446d6
- https://git.kernel.org/stable/c/72e4e3d7efc3b7d85f86abbe8b94f8e45074abe3
- https://git.kernel.org/stable/c/914e0100df3435bd14d09f397238e891cf9b7dce
- https://git.kernel.org/stable/c/9a220225efd6f58350bbb53fe70bdec08519267f



