← All Advisories

Linux Kernel bcmgenet Driver Enabling RBUF EEE and PM Bits Stops RX Traffic When MAC EEE Activates, Causing a Denial-of-Service Condition on Broadcom GENET Hardware

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-64125

Key Details

CVECVE-2026-64125
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-08-13
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsGeneral OT
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: bcmgenet: keep RBUF EEE/PM disabled

Setting RBUF_EEE_EN | RBUF_PM_EN in RBUF_ENERGY_CTRL breaks the RX

path on GENET hardware once MAC EEE becomes active. RX traffic stops

flowing while the link stays up and the usual descriptor/RX error

counters remain quiet. In that state the MAC still accepts frames

(rbuf_ovflow_cnt keeps climbing) but RBUF no longer forwards them to

DMA, so rx_packets is no longer incremented at the netdev level. On

some boards the corruption ends up as a paging fault in

skb_release_data via bcmgenet_rx_poll on an LPI exit.

Reproduced on Pi 4B (BCM2711 + BCM54213PE) and confirmed by Florian

Fainelli on an internal Broadcom 4908-family board with the same crash

signature. RBUF_PM_EN is not publicly documented.

This shows up more often now that phy_support_eee() enables EEE by

default, but it also affects older kernels as soon as TX LPI is

turned on via ethtool, so it is not specific to recent changes.

Always clear RBUF_EEE_EN | RBUF_PM_EN in bcmgenet_eee_enable_set so

the bits stay off across resets. UMAC and TBUF setup is left alone so

TX-side EEE keeps working. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-64125
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-64125