Vulnary
← back to the feed
Critical· 9.8official fix available

CVE-2024-53209

The Linux kernel's bnxt_en network driver can corrupt memory and MTU is changed while XDP multi‑attached. This occurs because the aggregation ring configuration can become out‑of‑sync when the MTU is changed while XDP is active, leading to random memory corruption and system crashes. This flaw has been resolved by updating the receive ring settings whenever the MTU changes. Updating the kernel to a version that includes this fix removes the vulnerability.

publishedDec 27, 2024
last modifiedAug 4, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
13th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 3, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Systems running the Linux kernel with the bnxt_en driver (e.g., servers using Broadcom NetXtreme-E network adapters).

02

Real-world impact

An attacker who can trigger an MTU change (or who already has local access) could cause the kernel to crash or potentially execute arbitrary code, resulting in denial of service or privilege escalation.

03

Why this severity

The CVSS v3.1 base score is 9.8 (Critical) because the vulnerability is network‑reachable, requires no privileges or user interaction, and can lead to full compromise of confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 01Obtain the latest Linux kernel update from your distribution that includes the commit fixing bnxt_en receive ring space parameters when XDP is active.
  2. 02Install or upgrade the kernel package.
  3. 03Reboot the system to load the updated kernel.

NVD-referenced vendor advisory (Linux kernel fix)

05

Timeline

  1. Dec 27, 2024 · Dec 27, 2024
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Aug 4, 2026 · 2d ago
    Advisory updated
    The NVD record was last revised.
  3. Aug 4, 2026 · 1d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →