In the Linux kernel, the following vulnerability has been resolved: net: stmmac: xgmac2: disable...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
net: stmmac: xgmac2: disable RBUE in default RX interrupt mask
Enabling the RX Buffer Unavailable (RBUE) interrupt is counterproductive and can trigger a MAC interrupt storm under heavy RX pressure. When the DMA runs out of RX descriptors it fires RBUE continuously until software refills the ring.
However, RBUE is redundant: the normal RX completion interrupt (RIE) already triggers NAPI, which processes completed descriptors and refills the ring, causing the DMA to resume. The RBUE handler itself only sets handle_rx - the same outcome as RIE.
On Agilex5 under heavy RX pressure, the MAC interrupt (which includes RBUE) was observed firing 1,821,811,555 times against only 2,618,627 actual RX completions - a ~695x ratio - confirming the severity of the storm.
RBUE does not provide OOM recovery. If page_pool is exhausted, stmmac_rx_refill() cannot advance the DMA tail pointer, the DMA stays suspended, and RBUE fires again on the next NAPI completion - a storm with no forward progress. This patch trades that storm for a clean stall with the same RX outcome. Proper OOM recovery is a pre-existing gap outside the scope of this fix.
Note: as a consequence of disabling RBUE, the rx_buf_unav_irq ethtool counter will always read 0 on XGMAC2 devices. This behaviour is already inconsistent across DWMAC core versions.
Remove RBUE from XGMAC_DMA_INT_DEFAULT_EN and XGMAC_DMA_INT_DEFAULT_RX to prevent the interrupt storm while keeping normal RX handling intact.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-93830
- https://git.kernel.org/stable/c/0b1a5d3647ce07c27a9fffefc11a8cbf7d7b25ce
- https://git.kernel.org/stable/c/87e2826ed2058747ddf014c082569a46bfadd96b
- https://git.kernel.org/stable/c/d3265c19b35d036bba327b36b5366bee76b0157c
- https://git.kernel.org/stable/c/6b3b91433d5f4eae6865cdaa96f40cd67849e1f6
- https://git.kernel.org/stable/c/74dbb85a6a254b5fc1f265a6cd61b2ba9d9221d7
- https://git.kernel.org/stable/c/7a10e54e42a8f73a8d731f5a281fc06bb41b9250
- https://git.kernel.org/stable/c/8c9d57b5dc098b84631d0b3559c84c499ea2170a
- https://github.com/advisories/GHSA-qh7q-28pc-c4hv