CVE-2026-97570

HIGHPre-NVD 8.18.1—
EchelonGraph scoreHIGH confidence

Score 8.1 from GitHub Security Advisory (severity: HIGH) published 2026-09-25. A secondary CVSS source baseline 8.1; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, secondary
Trending — 3 sources updated this week
8.1EG
EchelonGraph verdictPlan mitigationSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0.4%CVSS: 8.1Exploit: None knownExposed services: Not assessed

No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.

In the Linux kernel, the following vulnerability has been resolved:

bnxt_en: Bound SW TPA IDs to prevent crashes

FW supports up to 1024 concurrent TPAs, so the FW TPA ID is in the range 0..1023 (see commit ec4d8e7cf024 ("bnxt_en: Add TPA ID mapping logic for 57500 chips.")). bnxt_alloc_agg_idx is intended to wrap the FW ID down to a software ID which is used to index rxr->rx_tpa, and to generate a mapping between FW IDs and the wrapped software ID.

On a 57608 with firmware version 233, the firmware advertises 32 concurrent TPAs. As of the commit under fixes, bp->max_tpa on this NIC is set to 32.

If the software ID from bnxt_alloc_agg_idx is above 31, this results in an invalid address being loaded on this line:

tpa_info = &rxr->rx_tpa[agg_id];

because rx_tpa is allocated with only bp->max_tpa (32) entries. Writes to tpa_info later in the code are out of bounds.

This bug results in a crash at boot:

Oops: general protection fault, kernel NULL pointer dereference 0x8: 0000 [#1] SMP NOPTI RIP: 0010:bnxt_rx_pkt+0xc0/0x1560 RSP: 0018:ffffc900009b8c78 EFLAGS: 00010246 RAX: 0000000000000000 RBX: 0000000000000048 RCX: 0000000206682516 RDX: ffffc900009b8db4 RSI: 0000000000000000 RDI: 01ffffff038fe1c0 RBP: ffffc9006e687480 R08: ffffc9006e687000 R09: 0000000000003048 R10: 0000000000000480 R11: ffff8881c6083900 R12: 0000000006682516 R13: ffff8881c6095400 R14: 0000000000000016 R15: ffff8881c6b66680 FS: 0000000000000000(0000) GS:ffff88fef3c77000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fc8bda40584 CR3: 000000807c812001 CR4: 0000000008772ef0 PKRU: 55555554 Call Trace: ? __netif_receive_skb_list_core+0x1ca/0x250 __bnxt_poll_work+0x152/0x280 bnxt_poll_p5+0x1cd/0x480 __napi_poll+0x30/0x180 net_rx_action+0x20b/0x3b0 ? note_gp_changes+0x53/0xe0 ? tick_setup_sched_timer+0x180/0x180 ? __napi_schedule+0x9a/0xb0 ? bnxt_msix+0x24/0x30 handle_softirqs+0xdd/0x2c0 __irq_exit_rcu.llvm.3171231171502365008+0x47/0xf0 common_interrupt+0x85/0x90 asm_common_interrupt+0x22/0x40

This stack trace is from a crash triggered when an out of bounds rx_tpa is dereferenced. The invalid write mentioned above is silent in this particular crash.

Fix this by allocating rx_tpa with bp->max_tpa rounded up to the next power of 2 (bp->max_tpa_roundup_size) entries and masking the FW TPA ID with that size, so the wrapped ID can never index past the end of the array.

CVSS v3
8.1
EG Score
8.1HIGHhigh confidence
EG Risk
41
EG Risk 41/100CISA SSVC

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity81% × 45%
Exploitation0% × 40%
Automatability30% × 15%
CISA SSVC: Track at low or medium mission impact; Track or Attend at high (mission-essential systems).
Action: No fix is confirmed yet. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines at low or medium mission impact and sooner than that at high, and watch the vendor's advisory for the fix.
EPSS PROB
0.4%
EPSS %ILE
36th
KEV
Not listed

CISA SSVCTrack at low or medium mission impact; Track or Attend at high (mission-essential systems).

No fix is confirmed yet. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines at low or medium mission impact and sooner than that at high, and watch the vendor's advisory for the fix.

Exploitation none (no KEV listing, exploit record or EPSS ≥ 50%) · Automatable unknown (not published for this CVE) · Technical impact partial (CVSS below 9.0). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table

Published

September 25, 2026

Last Modified

September 25, 2026

Advisory Details (2)

Auto-updated Sep 25, 2026
No patch confirmed yet.
generic

bnxt_en: Bound SW TPA IDs to prevent crashes - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/c0aceaf65b70b3c000e70dd867f3a673015f24ca
generic

bnxt_en: Bound SW TPA IDs to prevent crashes - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/05cf64d171772c65bcdee76ee7163c35d9f55a89

Vendor Advisories for CVE-2026-97570(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Affected Packages

(1 across 1 ecosystem)
Debian:14(1)
PackageVulnerable rangeFix by version rangeDependents
linux6.12.100-1 ... 7.2~rc7-1~exp1 (179 versions)
  • every version up to 7.2.7-1: fixed in 7.2.7-1
—

Data Freshness Timeline

(refreshed 30× in last 7d / 49× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-10-05 05:57 UTCEG score recompute
  2. 2026-10-05 05:57 UTCGHSA enrichment
  3. 2026-10-04 23:23 UTCEPSS rescore
  4. 2026-10-04 19:01 UTCGHSA enrichment
  5. 2026-10-04 08:05 UTCGHSA enrichment
  6. 2026-10-03 21:10 UTCEG score recompute
  7. 2026-10-03 21:10 UTCGHSA enrichment
  8. 2026-10-03 14:26 UTCEPSS rescore
  9. 2026-10-03 10:14 UTCGHSA enrichment
  10. 2026-10-02 23:18 UTCEG score recompute
  11. 2026-10-02 23:18 UTCGHSA enrichment
  12. 2026-10-02 17:57 UTCEPSS rescore
  13. 2026-10-02 12:17 UTCGHSA enrichment
  14. 2026-10-02 01:22 UTCEG score recompute
  15. 2026-10-02 01:22 UTCGHSA enrichment
  16. 2026-10-01 19:51 UTCEPSS rescore
  17. 2026-10-01 14:27 UTCGHSA enrichment
  18. 2026-10-01 03:31 UTCGHSA enrichment
  19. 2026-09-30 16:36 UTCEG score recompute
  20. 2026-09-30 16:36 UTCGHSA enrichment
  21. 2026-09-30 15:04 UTCEPSS rescore
  22. 2026-09-30 05:10 UTCGHSA enrichment
  23. 2026-09-29 18:15 UTCEG score recompute
  24. 2026-09-29 18:15 UTCGHSA enrichment
  25. 2026-09-29 07:04 UTCEG score recompute
Show 24 more
  1. 2026-09-29 07:04 UTCGHSA enrichment
  2. 2026-09-28 20:07 UTCEG score recompute
  3. 2026-09-28 20:07 UTCGHSA enrichment
  4. 2026-09-28 13:52 UTCEPSS rescore
  5. 2026-09-28 13:52 UTCEPSS rescore
  6. 2026-09-28 09:07 UTCGHSA enrichment
  7. 2026-09-27 22:11 UTCEG score recompute
  8. 2026-09-27 22:11 UTCGHSA enrichment
  9. 2026-09-27 13:49 UTCEPSS rescore
  10. 2026-09-27 11:13 UTCGHSA enrichment
  11. 2026-09-27 00:17 UTCEG score recompute
  12. 2026-09-27 00:17 UTCGHSA enrichment
  13. 2026-09-26 15:59 UTCEPSS rescore
  14. 2026-09-26 13:17 UTCGHSA enrichment
  15. 2026-09-26 02:21 UTCEG score recompute
  16. 2026-09-26 02:21 UTCGHSA enrichment
  17. 2026-09-25 15:26 UTCEG score recompute
  18. 2026-09-25 15:26 UTCGHSA enrichment
  19. 2026-09-25 14:52 UTCEG score recompute▲ 8.10
  20. 2026-09-25 14:52 UTCGHSA enrichment
  21. 2026-09-25 14:49 UTCMITRE cvelistV5CVSS v3 → 8.1 · severity → HIGH
  22. 2026-09-25 11:29 UTCNVD update
  23. 2026-09-25 10:40 UTCEG score recompute
  24. 2026-09-25 10:27 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-97570?
CVE-2026-97570 is a high vulnerability published on September 25, 2026. In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Bound SW TPA IDs to prevent crashes FW supports up to 1024 concurrent TPAs, so the FW TPA ID is in the range 0..1023 (see commit ec4d8e7cf024 ("bnxt_en: Add TPA ID mapping logic for 57500 chips.")). bnxtallocagg_idx is…
When was CVE-2026-97570 disclosed?
CVE-2026-97570 was first published on September 25, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-97570 actively exploited?
CVE-2026-97570 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0.4% probability of exploitation in the next 30 days (36th percentile of EPSS-scored CVEs).
What is the CVSS score of CVE-2026-97570?
CVE-2026-97570 has a CVSS base score of 8.1 (a secondary CVSS source that NVD displays; NVD's own analysis pending).
How do I remediate CVE-2026-97570?
No fix for CVE-2026-97570 is confirmed yet. Until one is published, restrict network exposure of the affected system or apply the vendor's mitigation — for example, keep it off the internet or limit it to trusted networks — and watch the vendor's advisory for the fix. The vendor advisories EchelonGraph has for CVE-2026-97570 are linked in the Vendor Advisories panel on this page.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-97570

Explore →

Is Your Infrastructure Affected by CVE-2026-97570?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.