In the Linux kernel, the following vulnerability has been resolved: net: stmmac: restore NET_IP_ALIGN in the RX DMA offset Since the RX path was… (CVE-2026-90059)
A vulnerability in the Linux kernel's stmmac network driver caused misalignment of IP headers in received packets on architectures where NET_IP_ALIGN is 2, such as ARM32. This misalignment leads to alignment exceptions and kernel panics when processing certain network packets, including echo requests. The issue arose after a zero-copy conversion that omitted restoring NET_IP_ALIGN in the RX DMA offset. The vulnerability has been resolved by restoring NET_IP_ALIGN in the RX offset to ensure proper packet header alignment.
AI Analysis
Technical Summary
The Linux kernel's stmmac network driver had a vulnerability due to the RX path conversion to zero-copy, which omitted restoring NET_IP_ALIGN in the RX DMA offset. This omission caused IP headers to be misaligned on architectures like ARM32 where NET_IP_ALIGN equals 2. Misaligned IP headers cause fatal alignment exceptions and kernel panics when processing packets such as ICMP echo requests. The fix restores NET_IP_ALIGN in the RX offset, correcting the alignment and preventing the kernel panic. Previous attempts to fix alignment caused packet corruption and were reverted, but the current fix accounts properly for buffer sizes.
Potential Impact
On affected systems, particularly ARM32 architectures, receiving certain network packets (e.g., ICMP echo requests) causes kernel panics due to alignment exceptions. This results in denial of service as the kernel crashes and restarts. There is no impact on confidentiality or integrity reported, only availability due to system crashes.
Mitigation Recommendations
A fix is available that restores NET_IP_ALIGN in the RX DMA offset in the stmmac driver, correcting packet header alignment. Applying the official Linux kernel update that includes this fix will resolve the issue. No additional mitigation is required beyond applying the patch.
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: restore NET_IP_ALIGN in the RX DMA offset Since the RX path was… (CVE-2026-90059)
Description
A vulnerability in the Linux kernel's stmmac network driver caused misalignment of IP headers in received packets on architectures where NET_IP_ALIGN is 2, such as ARM32. This misalignment leads to alignment exceptions and kernel panics when processing certain network packets, including echo requests. The issue arose after a zero-copy conversion that omitted restoring NET_IP_ALIGN in the RX DMA offset. The vulnerability has been resolved by restoring NET_IP_ALIGN in the RX offset to ensure proper packet header alignment.
CVSS v3.1
Score 7.5high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's stmmac network driver had a vulnerability due to the RX path conversion to zero-copy, which omitted restoring NET_IP_ALIGN in the RX DMA offset. This omission caused IP headers to be misaligned on architectures like ARM32 where NET_IP_ALIGN equals 2. Misaligned IP headers cause fatal alignment exceptions and kernel panics when processing packets such as ICMP echo requests. The fix restores NET_IP_ALIGN in the RX offset, correcting the alignment and preventing the kernel panic. Previous attempts to fix alignment caused packet corruption and were reverted, but the current fix accounts properly for buffer sizes.
Potential Impact
On affected systems, particularly ARM32 architectures, receiving certain network packets (e.g., ICMP echo requests) causes kernel panics due to alignment exceptions. This results in denial of service as the kernel crashes and restarts. There is no impact on confidentiality or integrity reported, only availability due to system crashes.
Mitigation Recommendations
A fix is available that restores NET_IP_ALIGN in the RX DMA offset in the stmmac driver, correcting packet header alignment. Applying the official Linux kernel update that includes this fix will resolve the issue. No additional mitigation is required beyond applying the patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-j365-j246-5hmg
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-90059"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6aade52855bf5e2cf5edc1d0
Added to database: 09/19/2026, 01:28:08 UTC
Last enriched: 09/19/2026, 01:55:07 UTC
Last updated: 09/19/2026, 03:32:54 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.