{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-31563", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-03-09T15:48:24.116Z", "datePublished": "2026-04-24T14:35:44.610Z", "dateUpdated": "2026-08-05T12:23:31.809Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:23:31.809Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: Use dev_consume_skb_any() to free TX SKBs\n\nThe napi_consume_skb() function is not intended to be called in an IRQ\ndisabled context. However, after commit 6bc8a5098bf4 (\"net: macb: Fix\ntx_ptr_lock locking\"), the freeing of TX SKBs is performed with IRQs\ndisabled. To resolve the following call trace, use dev_consume_skb_any()\nfor freeing TX SKBs:\n WARNING: kernel/softirq.c:430 at __local_bh_enable_ip+0x174/0x188, CPU#0: ksoftirqd/0/15\n Modules linked in:\n CPU: 0 UID: 0 PID: 15 Comm: ksoftirqd/0 Not tainted 7.0.0-rc4-next-20260319-yocto-standard-dirty #37 PREEMPT\n Hardware name: ZynqMP ZCU102 Rev1.1 (DT)\n pstate: 200000c5 (nzCv daIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : __local_bh_enable_ip+0x174/0x188\n lr : local_bh_enable+0x24/0x38\n sp : ffff800082b3bb10\n x29: ffff800082b3bb10 x28: ffff0008031f3c00 x27: 000000000011ede0\n x26: ffff000800a7ff00 x25: ffff800083937ce8 x24: 0000000000017a80\n x23: ffff000803243a78 x22: 0000000000000040 x21: 0000000000000000\n x20: ffff000800394c80 x19: 0000000000000200 x18: 0000000000000001\n x17: 0000000000000001 x16: ffff000803240000 x15: 0000000000000000\n x14: ffffffffffffffff x13: 0000000000000028 x12: ffff000800395650\n x11: ffff8000821d1528 x10: ffff800081c2bc08 x9 : ffff800081c1e258\n x8 : 0000000100000301 x7 : ffff8000810426ec x6 : 0000000000000000\n x5 : 0000000000000001 x4 : 0000000000000001 x3 : 0000000000000000\n x2 : 0000000000000008 x1 : 0000000000000200 x0 : ffff8000810428dc\n Call trace:\n __local_bh_enable_ip+0x174/0x188 (P)\n local_bh_enable+0x24/0x38\n skb_attempt_defer_free+0x190/0x1d8\n napi_consume_skb+0x58/0x108\n macb_tx_poll+0x1a4/0x558\n __napi_poll+0x50/0x198\n net_rx_action+0x1f4/0x3d8\n handle_softirqs+0x16c/0x560\n run_ksoftirqd+0x44/0x80\n smpboot_thread_fn+0x1d8/0x338\n kthread+0x120/0x150\n ret_from_fork+0x10/0x20\n irq event stamp: 29751\n hardirqs last enabled at (29750): [] _raw_spin_unlock_irqrestore+0x44/0x88\n hardirqs last disabled at (29751): [] _raw_spin_lock_irqsave+0x38/0x98\n softirqs last enabled at (29150): [] handle_softirqs+0x504/0x560\n softirqs last disabled at (29153): [] run_ksoftirqd+0x44/0x80" } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:N - An unauthenticated remote peer can cause an affected MACB/GEM Ethernet interface to transmit packets, such as TCP resets, ICMP replies, or service responses, which drives TX completion and reaches the vulnerable SKB-freeing path. This is reachable over the network in a reasonable internet-facing or routed embedded deployment.\nAC:L - Once the affected driver is active and the interface transmits traffic, the path is deterministic: TX completion schedules NAPI and calls the invalid `napi_consume_skb()` path with IRQs disabled. The attacker does not need to win a race or shape kernel memory.\nPR:N - No local account, capability, device node access, or authentication is needed when remote packets induce kernel-generated replies or service traffic through the affected NIC. The vulnerable code is in normal packet transmit completion, not a privileged control path.\nUI:N - No victim user action is required beyond the system having the affected network interface up. Remote traffic can trigger the transmit and completion path automatically.\nS:U - The impact is within the same kernel and host security authority. There is no VM escape, IOMMU boundary crossing, or separate security scope involved.\nC:N - The bug is an invalid SKB consume helper used in IRQ-disabled context and the fix only changes the freeing API. I found no evidence of out-of-bounds access, use-after-free, arbitrary read, or information disclosure.\nI:N - The vulnerable path does not corrupt attacker-controlled kernel memory or provide a write primitive; it frees the TX SKB through an unsafe-context helper. There is no supported basis for integrity impact beyond availability.\nA:H - The reachable failure is a kernel WARNING in softirq/BH handling, and on systems using `panic_on_warn` this becomes a kernel panic from unauthenticated network-triggered traffic. Under the required higher-severity rule, the availability impact is scored high for that reasonable deployment." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/ethernet/cadence/macb_main.c" ], "versions": [ { "version": "aeeafeb29b1b270302a9a85a13f7d70a68a3b9e6", "lessThan": "92e7081f0c79d9073087e54bab745bb184192c2e", "status": "affected", "versionType": "git" }, { "version": "5430388a81113e62a2d48b5d7dc1e76231908ebf", "lessThan": "78c8b090a3d5c1689dc989861b0163180db2b3f8", "status": "affected", "versionType": "git" }, { "version": "7db8aa3fc4ed0a2928246747b2514b0741a8187e", "lessThan": "984350b37372f79f71d4f0a5264c640e40daf9ce", "status": "affected", "versionType": "git" }, { "version": "6bc8a5098bf4a365c4086a4a4130bfab10a58260", "lessThan": "f4bc91398b579730284328322365afa77a9d568f", "status": "affected", "versionType": "git" }, { "version": "6bc8a5098bf4a365c4086a4a4130bfab10a58260", "lessThan": "ca4d05afb4683d685bb2c6fccae4386c478f524a", "status": "affected", "versionType": "git" }, { "version": "6bc8a5098bf4a365c4086a4a4130bfab10a58260", "lessThan": "647b8a2fe474474704110db6bd07f7a139e621eb", "status": "affected", "versionType": "git" }, { "version": "a4cb0a15ab8e6d06c08229a2c7bdbe1f2454473f", "status": "affected", "versionType": "git" }, { "version": "6.1.151", "lessThan": "6.1.168", "status": "affected", "versionType": "semver" }, { "version": "6.6.105", "lessThan": "6.6.131", "status": "affected", "versionType": "semver" }, { "version": "6.12.46", "lessThan": "6.12.80", "status": "affected", "versionType": "semver" }, { "version": "6.16.6", "lessThan": "6.17", "status": "affected", "versionType": "semver" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/ethernet/cadence/macb_main.c" ], "versions": [ { "version": "6.17", "status": "affected" }, { "version": "0", "lessThan": "6.17", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.168", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.131", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.80", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.21", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.19.11", "lessThanOrEqual": "6.19.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.0", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.1.151", "versionEndExcluding": "6.1.168" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.6.105", "versionEndExcluding": "6.6.131" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.12.46", "versionEndExcluding": "6.12.80" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.17", "versionEndExcluding": "6.18.21" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.17", "versionEndExcluding": "6.19.11" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.17", "versionEndExcluding": "7.0" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.16.6" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/92e7081f0c79d9073087e54bab745bb184192c2e" }, { "url": "https://git.kernel.org/stable/c/78c8b090a3d5c1689dc989861b0163180db2b3f8" }, { "url": "https://git.kernel.org/stable/c/984350b37372f79f71d4f0a5264c640e40daf9ce" }, { "url": "https://git.kernel.org/stable/c/f4bc91398b579730284328322365afa77a9d568f" }, { "url": "https://git.kernel.org/stable/c/ca4d05afb4683d685bb2c6fccae4386c478f524a" }, { "url": "https://git.kernel.org/stable/c/647b8a2fe474474704110db6bd07f7a139e621eb" } ], "title": "net: macb: Use dev_consume_skb_any() to free TX SKBs", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "x_adpType": "supplier", "providerMetadata": { "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e", "shortName": "siemens-SADP", "dateUpdated": "2026-07-14T12:48:21.980Z" }, "affected": [ { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.6", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.6", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.6", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.6", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.6", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" } ], "references": [ { "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html" }, { "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html" } ] } ] } }