Linux aws: In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting RBUF_EEE_EN | RBUF_PM_EN in… (CVE-2026-64125)
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting RBUF_EEE_EN | RBUF_PM_EN in RBUF_ENERGY_CTRL breaks the RX path on GENET hardware once MAC EEE becomes active. RX traffic stops flowing while the link stays up and the usual descriptor/RX error counters remain quiet. In that state the MAC still accepts frames (rbuf_ovflow_cnt keeps climbing) but RBUF no longer forwards them to DMA, so rx_packets is no longer incremented at the netdev level. On some boards the corruption ends up as a paging fault in skb_release_data via bcmgenet_rx_poll on an LPI exit. Reproduced on Pi 4B (BCM2711 + BCM54213PE) and confirmed by Florian Fainelli on an internal Broadcom 4908-family board with the same crash signature. RBUF_PM_EN is not publicly documented. This shows up more often now that phy_support_eee() enables EEE by default, but it also affects older kernels as soon as TX LPI is turned on via ethtool, so it is not specific to recent changes. Always clear RBUF_EEE_EN | RBUF_PM_EN in bcmgenet_eee_enable_set so the bits stay off across resets. UMAC and TBUF setup is left alone so TX-side EEE keeps working.
AI Analysis
Technical Summary
CVE-2026-64125 is a Linux kernel vulnerability in the bcmgenet network driver where enabling RBUF_EEE_EN or RBUF_PM_EN flags in RBUF_ENERGY_CTRL breaks the RX path on Broadcom GENET hardware once MAC EEE becomes active. This causes RX traffic to stop flowing while the link remains up, with no RX errors reported. The MAC continues to accept frames, but they are not forwarded to DMA, preventing packet reception at the netdev level. On some hardware, this leads to a paging fault during skb_release_data on LPI exit. The issue has been reproduced on Raspberry Pi 4B (BCM2711 + BCM54213PE) and confirmed on Broadcom 4908-family boards. The vulnerability is exacerbated by phy_support_eee() enabling EEE by default and affects older kernels when TX LPI is enabled via ethtool. The vulnerability is fixed in Linux kernel versions 5.15.0-1112.119~20.04.1 and later.
Potential Impact
Exploitation of this vulnerability results in a denial of service condition where RX traffic stops flowing despite the network link remaining up. This can cause network communication failures and potential kernel crashes on affected hardware. The issue impacts system availability and network reliability on affected Linux kernel versions running on Broadcom GENET hardware.
Mitigation Recommendations
A patch is available for this vulnerability. Users should update affected Linux kernel versions to 5.15.0-1112.119~20.04.1 or later as provided by their distribution vendor. After applying the update, a system reboot is required to activate the fix. Due to an ABI change, recompilation and reinstallation of third-party kernel modules may be necessary. Follow vendor instructions for updating and rebuilding kernel modules. No other mitigation is indicated by the vendor advisory.
Linux aws: In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting RBUF_EEE_EN | RBUF_PM_EN in… (CVE-2026-64125)
Description
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting RBUF_EEE_EN | RBUF_PM_EN in RBUF_ENERGY_CTRL breaks the RX path on GENET hardware once MAC EEE becomes active. RX traffic stops flowing while the link stays up and the usual descriptor/RX error counters remain quiet. In that state the MAC still accepts frames (rbuf_ovflow_cnt keeps climbing) but RBUF no longer forwards them to DMA, so rx_packets is no longer incremented at the netdev level. On some boards the corruption ends up as a paging fault in skb_release_data via bcmgenet_rx_poll on an LPI exit. Reproduced on Pi 4B (BCM2711 + BCM54213PE) and confirmed by Florian Fainelli on an internal Broadcom 4908-family board with the same crash signature. RBUF_PM_EN is not publicly documented. This shows up more often now that phy_support_eee() enables EEE by default, but it also affects older kernels as soon as TX LPI is turned on via ethtool, so it is not specific to recent changes. Always clear RBUF_EEE_EN | RBUF_PM_EN in bcmgenet_eee_enable_set so the bits stay off across resets. UMAC and TBUF setup is left alone so TX-side EEE keeps working.
CVSS v3.1
Score 9.8critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-64125 is a Linux kernel vulnerability in the bcmgenet network driver where enabling RBUF_EEE_EN or RBUF_PM_EN flags in RBUF_ENERGY_CTRL breaks the RX path on Broadcom GENET hardware once MAC EEE becomes active. This causes RX traffic to stop flowing while the link remains up, with no RX errors reported. The MAC continues to accept frames, but they are not forwarded to DMA, preventing packet reception at the netdev level. On some hardware, this leads to a paging fault during skb_release_data on LPI exit. The issue has been reproduced on Raspberry Pi 4B (BCM2711 + BCM54213PE) and confirmed on Broadcom 4908-family boards. The vulnerability is exacerbated by phy_support_eee() enabling EEE by default and affects older kernels when TX LPI is enabled via ethtool. The vulnerability is fixed in Linux kernel versions 5.15.0-1112.119~20.04.1 and later.
Potential Impact
Exploitation of this vulnerability results in a denial of service condition where RX traffic stops flowing despite the network link remaining up. This can cause network communication failures and potential kernel crashes on affected hardware. The issue impacts system availability and network reliability on affected Linux kernel versions running on Broadcom GENET hardware.
Mitigation Recommendations
A patch is available for this vulnerability. Users should update affected Linux kernel versions to 5.15.0-1112.119~20.04.1 or later as provided by their distribution vendor. After applying the update, a system reboot is required to activate the fix. Due to an ABI change, recompilation and reinstallation of third-party kernel modules may be necessary. Follow vendor instructions for updating and rebuilding kernel modules. No other mitigation is indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-89rr-cfw2-c9px
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64125"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a5d27a82a4a8d598912af00
Added to database: 07/19/2026, 19:38:16 UTC
Last enriched: 08/22/2026, 14:28:30 UTC
Last updated: 08/31/2026, 10:52:10 UTC
Views: 45
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.