PT-2026-2527 · Bnx2X+7 · Bnx2X+7

Published

2025-12-08

·

Updated

2026-05-11

·

CVE-2025-68795

CVSS v2.0

5.0

Medium

VectorAV:L/AC:H/Au:S/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The ethtool utility, specifically the -S command, is susceptible to a buffer overflow when querying device statistics. This occurs because the number of statistics can change between the calls to determine the buffer size, string names, and actual values. Certain drivers, such as mlx5, bnx2x, bna, and ksz884x, utilize dynamic counters, increasing the likelihood of this issue. While some drivers attempt internal handling, they rely on potentially outdated information. The issue arises from a mismatch between the userspace buffer size and the actual number of statistics returned. The fix implemented prevents the overflow by not returning any data when a mismatch is detected, resulting in either no output or zeroed statistics, which is considered more predictable than incorrect data. The patch addresses the buffer overflow but does not resolve the underlying race condition. The vulnerability exists between separate ioctl calls when the RTNL lock is released. The code includes a check to ensure stats.n stats is not zero to prevent regressions in userspace applications that may not populate this value.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-74411
BDU:2026-00713
CVE-2025-68795
ECHO-2B94-B33F-A713
MGASA-2026-0017
MGASA-2026-0018
OPENSUSE-SU-2026:20287-1
SUSE-SU-2026:0447-1
SUSE-SU-2026:0472-1
SUSE-SU-2026:0473-1
SUSE-SU-2026:0587-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8116-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8177-1
USN-8177-2
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8183-1
USN-8183-2
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8243-1
USN-8245-1
USN-8257-1
USN-8258-1
USN-8260-1
USN-8261-1
USN-8265-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu
Bna
Bnx2X
Ethtool
Ksz884X
Mlx5