Description
In the Linux kernel, the following vulnerability has been resolved:

hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed

Previously, hinic3_send_one_skb() cached the skb fragment count before
calling hinic3_tx_offload(). If hinic3_tx_csum() falls back to
skb_checksum_help() for unsupported tunnel packets, the skb may be
linearized. Continuing to build the TX descriptor with the stale
fragment count leads to a descriptor mismatch, which can trigger
out-of-bounds DMA reads or IOMMU faults.

Furthermore, the old code ignored the return value of skb_checksum_help(),
transmitting corrupted packets with incomplete checksums upon failure.

Fix this by:
1. Moving the hinic3_tx_offload() call before calculating 'num_sge' to
ensure the correct fragment count is used if the SKB is linearized.
2. Propagating skb_checksum_help() errors and returning
HINIC3_TX_OFFLOAD_INVALID to properly drop the skb.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption that could lead to privilege elevation or remote code execution (inferred)
Action: Patch Kernel
AI Analysis

Impact

The flaw exists in the hinic3 NIC driver where it caches an SKB fragment count before calling a checksum offload routine. If a checksum helper linearizes the SKB, the driver continues to use the stale fragment count, causing its generated TX descriptor to misrepresent the packet structure. This mismatch can trigger out‑of‑bounds DMA reads or IOMMU faults, exposing kernel memory to corruption. In addition, the driver previously ignored the return value of the checksum helper, which meant corrupted packets could be transmitted. The net effect is potential kernel memory corruption that, if exploited, could allow a local attacker to elevate privileges or execute code in kernel mode (inferred).

Affected Systems

All Linux kernel releases that incorporate the hinic3 NIC driver before the current patch are vulnerable. The vulnerability applies to any system running a Linux kernel with the buggy hinic3 implementation, regardless of distribution specifics. No precise version range is disclosed, so any kernel containing the original code path is considered at risk.

Risk and Exploitability

The CVSS score of 7.1 signals high severity, and the EPSS score of < 1% indicates a low but non‑zero likelihood of exploitation in the wild. This issue is not included in CISA’s KEV catalog. Exploitation would require an attacker to send or manipulate packets that reach the affected NIC, implying local or compromised‑host attackers are the primary threat actors. While remote exploitation probability is uncertain, the potential for kernel memory corruption warrants serious consideration and swift mitigation.

Generated by OpenCVE AI on September 20, 2026 at 03:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the fix for this issue and reboot the system.
  • If an immediate kernel upgrade is not possible, disable the hinic3 driver by unbinding the NIC from the driver or uninstalling the driver module.
  • As a temporary measure, disable packet offloading for the interface using `ethtool -K <interface> tx off` or `ethtool -K <interface> rx off` to reduce the chances that the checksum helper is invoked.

Generated by OpenCVE AI on September 20, 2026 at 03:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-125
CWE-252

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed Previously, hinic3_send_one_skb() cached the skb fragment count before calling hinic3_tx_offload(). If hinic3_tx_csum() falls back to skb_checksum_help() for unsupported tunnel packets, the skb may be linearized. Continuing to build the TX descriptor with the stale fragment count leads to a descriptor mismatch, which can trigger out-of-bounds DMA reads or IOMMU faults. Furthermore, the old code ignored the return value of skb_checksum_help(), transmitting corrupted packets with incomplete checksums upon failure. Fix this by: 1. Moving the hinic3_tx_offload() call before calculating 'num_sge' to ensure the correct fragment count is used if the SKB is linearized. 2. Propagating skb_checksum_help() errors and returning HINIC3_TX_OFFLOAD_INVALID to properly drop the skb.
Title hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:22.491Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90145

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:07.350

Modified: 2026-09-18T18:17:43.853

Link: CVE-2026-90145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:45:12Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read

  • CWE-252

    Unchecked Return Value