Skip to main content
Vulnerability Database/CVE-2026-98052

CVE-2026-98052: Linux Kernel bcmasp Use-After-Free Flaw

CVE-2026-98052 is a use-after-free vulnerability in the Linux kernel bcmasp network driver that can cause premature memory deallocation. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-98052 Overview

CVE-2026-98052 is a use-after-free vulnerability in the Linux kernel's Broadcom ASP 2.0 Ethernet driver (bcmasp). The flaw resides in bcmasp_xmit(), which failed to clear the txcb->last flag before writing each transmit descriptor. Non-final SKB fragments inherited stale last == true values from prior transmissions, causing bcmasp_tx_reclaim() to invoke dev_consume_skb_any() mid-SKB and free an sk_buff while remaining fragments were still in flight.

Critical Impact

A local attacker with the ability to trigger network transmit activity on affected systems can induce a use-after-free condition on sk_buff structures, enabling kernel memory corruption, denial of service, or potential privilege escalation.

Affected Products

  • Linux kernel versions containing the bcmasp driver prior to the fix commits
  • Broadcom ASP 2.0 Ethernet controllers (used in Raspberry Pi 5 and similar Broadcom-based platforms)
  • Stable kernel branches patched via commits 17e6ad4, 18e5e0e, 47a5cec, and 9b26b54

Discovery Timeline

  • 2026-09-25 - CVE-2026-98052 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-98052

Vulnerability Analysis

The bcmasp driver manages the transmit path by populating per-descriptor control blocks (txcb) that track whether a descriptor represents the final fragment of an SKB. The last field signals bcmasp_tx_reclaim() when it is safe to release the owning sk_buff back to the kernel.

The original bcmasp_xmit() logic only wrote txcb->last = true on the terminal fragment. Non-final fragments did not reset the field, so any residual true from a prior transmission persisted. When tx_spb_ring_full() underreported ring fullness, the driver reused descriptor slots still holding stale metadata. The reclaim path then observed last == true partway through a multi-fragment SKB and prematurely freed the socket buffer while subsequent fragments remained queued for DMA.

Freeing an sk_buff while its backing memory is still referenced by in-flight descriptors produces a use-after-free. Subsequent DMA reads, reclaim passes, or allocator reuse of the freed slab object can corrupt kernel memory or leak sensitive data.

Root Cause

The root cause is incomplete descriptor state initialization. txcb->last was treated as write-once-per-final-fragment rather than write-every-descriptor. The fix unconditionally clears txcb->last before the conditional set, ensuring every descriptor begins from a known false state.

Attack Vector

Exploitation requires local access and the ability to generate network transmit traffic through the affected Broadcom ASP interface. An attacker who can issue multi-fragment transmissions and influence ring occupancy timing can race the reclaim path to trigger the premature free. The vulnerability does not require elevated privileges beyond standard local user access.

No public exploit code is available. Technical details are documented in the upstream patches referenced in the external references.

Detection Methods for CVE-2026-98052

Indicators of Compromise

  • Kernel log entries from KASAN or SLUB debug reporting use-after-free reads or writes within bcmasp_tx_reclaim or related sk_buff destructor paths
  • Unexpected network interface resets, transmit queue stalls, or dropped multi-fragment packets on bcmasp-managed interfaces
  • System crashes or Oops traces originating from the bcmasp transmit reclaim path

Detection Strategies

  • Enable CONFIG_KASAN on test and pre-production kernels to surface the use-after-free during transmit workloads with fragmented SKBs
  • Audit running kernel versions against the fix commits 17e6ad4, 18e5e0e, 47a5cec, and 9b26b54 to identify unpatched hosts
  • Correlate dmesg output with network interface statistics for abnormal reclaim behavior on Broadcom ASP hardware

Monitoring Recommendations

  • Forward kernel ring buffer events to a centralized logging pipeline and alert on bcmasp subsystem errors
  • Track transmit queue depth and drop counters on affected interfaces to detect ring-fullness anomalies that precede the race
  • Monitor for unexpected process termination or kernel panics on hosts using Broadcom ASP Ethernet controllers

How to Mitigate CVE-2026-98052

Immediate Actions Required

  • Apply the upstream Linux kernel patches referenced in the stable tree commits as soon as vendor builds are available
  • Inventory systems using Broadcom ASP 2.0 Ethernet controllers and prioritize patching for multi-tenant or shared-access hosts
  • Restrict local shell access on affected systems until patched kernels are deployed

Patch Information

The fix clears txcb->last unconditionally before the conditional set in bcmasp_xmit(). Patches are available in the mainline and stable Linux kernel trees:

Workarounds

  • Where patching is not immediately possible, disable or unload the bcmasp driver and route traffic through an alternate interface
  • Limit local user access and avoid untrusted workloads on hosts exposing the vulnerable driver
  • Deploy kernel live-patching if supported by your distribution and the patch is backported
bash
# Check running kernel and bcmasp driver status
uname -r
lsmod | grep bcmasp

# Temporarily unload the driver if an alternate NIC is available
sudo modprobe -r bcmasp

# Blacklist to prevent reload at boot
echo "blacklist bcmasp" | sudo tee /etc/modprobe.d/blacklist-bcmasp.conf
sudo update-initramfs -u

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.