{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "bd649c5cc958169b8a8a3e77ea926d92d472b02a"
            },
            {
              "fixed": "8ade95619cbfd1fc57f0f1a9a5ebdca2345a8d27"
            },
            {
              "fixed": "0596a7caa6fc283e142716739099c038d8714082"
            },
            {
              "fixed": "5ce7f36c334d723954855ac769ede2fe0e8f89c8"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "0997443906b96a051011f220a61e6dce4602ec54"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.12.20"
            },
            {
              "fixed": "6.13"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.53"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97574.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Don't free the live ring's TPA state on queue restart failure\n\nbnxt_queue_mem_alloc() shallow copies the live RX ring into the clone:\n\n  memcpy(clone, rxr, sizeof(*rxr));\n\nthe code currently clears pointers that the clone owns (such as\nrx_agg_bmap), but rx_tpa and rx_tpa_idx_map are left pointing at memory\nof the live ring that was cloned.\n\nIf an allocation failure happens later and the err_free_tpa_info label\nis taken, the live ring's memory can be freed while still in use.\n\nFix this by initializing the clone's pointers to NULL to prevent live\nring state from being freed inadvertently.",
  "id": "CVE-2026-97574",
  "modified": "2026-09-27T03:30:19.597513860Z",
  "published": "2026-09-25T10:21:58.062Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0596a7caa6fc283e142716739099c038d8714082"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/5ce7f36c334d723954855ac769ede2fe0e8f89c8"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/8ade95619cbfd1fc57f0f1a9a5ebdca2345a8d27"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97574.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97574"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "bnxt_en: Don't free the live ring's TPA state on queue restart failure"
}