CVE-2026-74697: bnxt_en: Disable EOP for TPA on all chips to prevent data corruption

Published Aug 22, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

bnxten: Disable EOP for TPA on all chips to prevent data corruption

EOP (End of frame padding) on the AGG ring may cause overlapping of zero padding at the end of one segment with the next segment's data. If Relaxed Ordering (RO) is enabled, the zero padding may overwrite valid data in the next segment and corrupt the data. Older chips (P5 and older) do not automatically disable RO when EOP is enabled. On some ARM systems, data corruption was reported on 57508 (P5) chips with RO enabled.

Always disable EOP on all chips on the AGG rings when TPA is enabled to fix the data corruption.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade bnxt_en to a version that resolves this vulnerability.

    Patch 57508
  2. Configuration

    Disable EOP on all chips on the AGG rings when TPA is enabled to prevent data corruption. For older chips (e.g., 57508 / P5 and older) do not automatically disable RO when EOP is enabled; keep RO behavior but ensure EOP is disabled for TPA on all chips with RO enabled.

    bnxt_en EOP (End of frame padding) = disabled

Event History

Aug 22, 2026
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
Description
Data Sourced
via NVD·04:16 PM
Description

Frequently Asked Questions

1

Which systems are most likely to experience corruption?

Systems using the bnxt_en driver with TPA enabled and Relaxed Ordering enabled are exposed to this corruption condition. The issue is specifically reported on some ARM systems using 57508 (P5) chips, and P5 and older chips do not automatically disable Relaxed Ordering when EOP is enabled.

2

What configuration is required for the problem to occur?

The condition involves EOP enabled on AGG rings while TPA and Relaxed Ordering are enabled. Under those conditions, zero padding at the end of one segment can overlap and overwrite valid data in the next segment.

3

What mitigation is described if an update cannot be applied immediately?

Disable EOP on AGG rings when TPA is enabled. This prevents the overlapping zero padding that can corrupt subsequent segment data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203