In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting RBUF_EEE_EN | RBUF_PM_EN in… (CVE-2026-64125)
A vulnerability in the Linux kernel's bcmgenet network driver causes the RX path to stop processing incoming packets when certain energy-efficient Ethernet (EEE) control bits are enabled. This results in halted RX traffic while the link remains up, with no usual error counters triggered. The issue can lead to system crashes on some hardware when exiting low power idle states. The vulnerability has been resolved by ensuring these problematic bits remain disabled across resets, preserving TX-side EEE functionality.
AI Analysis
Technical Summary
The Linux kernel vulnerability CVE-2026-64125 involves the bcmgenet network driver where enabling RBUF_EEE_EN and RBUF_PM_EN bits in the RBUF_ENERGY_CTRL register breaks the receive (RX) path on GENET hardware once MAC EEE activates. Although the link stays up, RX traffic stops flowing and no RX errors are reported, while the MAC continues to accept frames that are not forwarded to DMA. On some boards, this leads to a paging fault crash during low power idle (LPI) exit. The issue is triggered by default enabling of EEE and affects older kernels when TX LPI is enabled. The fix involves always clearing these bits in bcmgenet_eee_enable_set to keep them disabled across resets, while leaving TX EEE operational.
Potential Impact
RX traffic stops flowing on affected GENET hardware when EEE is enabled, causing network receive functionality to silently fail without error counters. This can lead to degraded network performance and, on some hardware, system crashes due to paging faults during low power idle exit. The link remains up, potentially misleading monitoring systems. The vulnerability affects network reliability and system stability on impacted devices.
Mitigation Recommendations
A fix is available that ensures the RBUF_EEE_EN and RBUF_PM_EN bits remain disabled across resets in the bcmgenet driver, preserving RX functionality while allowing TX EEE to continue working. Users should apply the updated Linux kernel version containing this fix. Since this is a kernel-level issue, upgrading to the patched kernel release is the recommended remediation. Patch status is not explicitly confirmed in the provided data; users should consult the official Linux kernel advisories or vendor updates for the exact patched versions and apply them accordingly.
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting RBUF_EEE_EN | RBUF_PM_EN in… (CVE-2026-64125)
Description
A vulnerability in the Linux kernel's bcmgenet network driver causes the RX path to stop processing incoming packets when certain energy-efficient Ethernet (EEE) control bits are enabled. This results in halted RX traffic while the link remains up, with no usual error counters triggered. The issue can lead to system crashes on some hardware when exiting low power idle states. The vulnerability has been resolved by ensuring these problematic bits remain disabled across resets, preserving TX-side EEE functionality.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability CVE-2026-64125 involves the bcmgenet network driver where enabling RBUF_EEE_EN and RBUF_PM_EN bits in the RBUF_ENERGY_CTRL register breaks the receive (RX) path on GENET hardware once MAC EEE activates. Although the link stays up, RX traffic stops flowing and no RX errors are reported, while the MAC continues to accept frames that are not forwarded to DMA. On some boards, this leads to a paging fault crash during low power idle (LPI) exit. The issue is triggered by default enabling of EEE and affects older kernels when TX LPI is enabled. The fix involves always clearing these bits in bcmgenet_eee_enable_set to keep them disabled across resets, while leaving TX EEE operational.
Potential Impact
RX traffic stops flowing on affected GENET hardware when EEE is enabled, causing network receive functionality to silently fail without error counters. This can lead to degraded network performance and, on some hardware, system crashes due to paging faults during low power idle exit. The link remains up, potentially misleading monitoring systems. The vulnerability affects network reliability and system stability on impacted devices.
Mitigation Recommendations
A fix is available that ensures the RBUF_EEE_EN and RBUF_PM_EN bits remain disabled across resets in the bcmgenet driver, preserving RX functionality while allowing TX EEE to continue working. Users should apply the updated Linux kernel version containing this fix. Since this is a kernel-level issue, upgrading to the patched kernel release is the recommended remediation. Patch status is not explicitly confirmed in the provided data; users should consult the official Linux kernel advisories or vendor updates for the exact patched versions and apply them accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-89rr-cfw2-c9px
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64125"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5d27a82a4a8d598912af00
Added to database: 07/19/2026, 19:38:16 UTC
Last enriched: 07/19/2026, 19:45:37 UTC
Last updated: 07/20/2026, 17:26:47 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.