Description
In the Linux kernel, the following vulnerability has been resolved:

bnxt_en: Fix call to hardware monitoring event handler

The first parameter of hwmon_notify_event() is supposed to be the hardware
monitoring device. The bnxt driver calls it with the platform device as
first parameter instead. This API break results in undefined behavior and
may result in a crash.

Pass the hardware monitoring device as parameter instead to fix the
problem.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The bnxt_en networking driver in the Linux kernel incorrectly invokes hwmon_notify_event with a platform device instead of the intended hardware monitoring device. This misuse of the API produces undefined behavior that can result in a kernel panic, rendering the operating system non‑responsive and effectively causing a denial of service to all processes and users.

Affected Systems

Linux kernel systems that load or use the bnxt_en driver module, which is included in many mainstream distributions. Any system with the module present may be affected; no specific hardware vendor information is supplied.

Risk and Exploitability

The EPSS value is less than 1 % and the vulnerability is not catalogued as a known exploited vulnerability, indicating a very low probability of being targeted in the wild. Exploitation would require the ability to load or modify a kernel module—a capability normally restricted to privileged users. Consequently, the threat is largely limited to environments where an adversary can obtain local privileged access or a compromised system image.

Generated by OpenCVE AI on September 20, 2026 at 04:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install a kernel version that includes the patch referenced in the kernel commit history; update to the latest stable release from your distribution.
  • If a kernel upgrade is not currently feasible, disable the bnxt_en module by adding it to the blacklist or removing the module so the driver cannot be loaded.
  • Enable kernel module signing enforcement to prevent tampering with the bnxt_en driver on systems that support signed modules.

Generated by OpenCVE AI on September 20, 2026 at 04:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-279

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix call to hardware monitoring event handler The first parameter of hwmon_notify_event() is supposed to be the hardware monitoring device. The bnxt driver calls it with the platform device as first parameter instead. This API break results in undefined behavior and may result in a crash. Pass the hardware monitoring device as parameter instead to fix the problem.
Title bnxt_en: Fix call to hardware monitoring event handler
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:12.213Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90101

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:01.793

Modified: 2026-09-17T17:17:01.793

Link: CVE-2026-90101

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses
  • CWE-279

    Incorrect Execution-Assigned Permissions