CVE-2026-52983: Linux Kernel
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix BQL imbalance in TX path Fix a possible BQL imbalance in airoha_dev_xmit(), where inflight packets are accounted only for the AIROHA_NUM_TX_RING netdev TX queues. The queue index is computed as: qid = skb_get_queue_mapping(skb) % ARRAY_SIZE(qdma->q_tx) txq = netdev_get_tx_queue(dev, qid); However, airoha_qdma_tx_napi_poll() accounts completions across all netdev TX queues (num_tx_queues), leading to inconsistent BQL accounting. Also reset all netdev TX queues in the ndo_stop callback.
Affected products
- Linux Linux Kernel: from 6.12.91, before 6.18.33 (fixed in 6.18.33); from 6.19, before 7.0.10 (fixed in 7.0.10); version 7.1 only
Published 2026-06-24. Last modified 2026-07-14.