Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/bng_re: return a timeout when firmware responses stall

__wait_for_resp() documents that it returns a non-zero error when a
firmware command does not complete, and bng_re_rcfw_send_message() already
marks the firmware as stalled when the helper returns -ENODEV.

However, the helper ignores wait_event_timeout() expiry. If the response
slot remains in use after the timeout and after the polled CREQ service
attempt, the loop starts another full timeout period and can repeat
forever.

Return -ENODEV after a timed out wait that still has no response. The
existing caller then marks FIRMWARE_STALL_DETECTED and returns
-ETIMEDOUT to the command issuer.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, the RDMA/bng_re component can enter an endless loop when the firmware stalls. The helper function ignores the wait_event_timeout expiration, so a stalled firmware response can cause the system to repeatedly wait, each time restarting a full timeout period. This behavior can lock the RDMA path indefinitely, leading to a denial of service in RDMA operations.

Affected Systems

The vulnerability affects the Linux kernel RDMA/bng_re driver. No specific kernel versions are listed in the CNA data, implying that all supported releases of the Linux kernel that include the bng_re driver may be impacted.

Risk and Exploitability

The CVSS score is not disclosed, but the EPSS score is below 1% and the vulnerability is not in CISA KEV, suggesting a low exploitation probability. The flaw requires access to the RDMA subsystem, so an attacker would need local privileges or would need to compromise a component that interacts with RDMA; there is no known remote exploitation vector. If exploited, an attacker could stall RDMA commands indefinitely, effectively disrupting network services relying on RDMA.

Generated by OpenCVE AI on September 19, 2026 at 07:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to the latest version once a vendor patch for CVE-2026-93153 is available.
  • If RDMA is not required, disable or remove the bng_re driver to eliminate the risk.
  • Monitor kernel logs for repeated bng_re timeouts and, if necessary, apply a temporary source-code modification that enforces the wait_event_timeout expiration to prevent endless loops.

Generated by OpenCVE AI on September 19, 2026 at 07:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-730

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/bng_re: return a timeout when firmware responses stall __wait_for_resp() documents that it returns a non-zero error when a firmware command does not complete, and bng_re_rcfw_send_message() already marks the firmware as stalled when the helper returns -ENODEV. However, the helper ignores wait_event_timeout() expiry. If the response slot remains in use after the timeout and after the polled CREQ service attempt, the loop starts another full timeout period and can repeat forever. Return -ENODEV after a timed out wait that still has no response. The existing caller then marks FIRMWARE_STALL_DETECTED and returns -ETIMEDOUT to the command issuer.
Title RDMA/bng_re: return a timeout when firmware responses stall
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:49.443Z

Reserved: 2026-09-17T16:02:15.089Z

Link: CVE-2026-93153

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:10.607

Modified: 2026-09-17T17:18:10.607

Link: CVE-2026-93153

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:00:11Z

Weaknesses