{"id":"CVE-2026-80998","title":"kernel: net: bnxt: ring the doorbell when SW USO exits early (CVE-2026-80998)","summary":"A flaw was found in the Linux kernel's `bnxt` network driver. When processing a burst of packets, the driver may fail to notify the network device (ring the doorbell) if the Software UDP Segmentation Offload (SW USO) path exits prematurely…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-841","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T20:26:53+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80998.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80998.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80998"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532129"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80998"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80998"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80998.mbox"},{"url":"https://git.kernel.org/stable/c/48d1c9665db6e3d4aeca62eb669377162ebc6fdf"},{"url":"https://git.kernel.org/stable/c/4e15e89faac9f308baeb01f46c13a051814d2449"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00467,"epssPercentile":0.39515,"scores":{"vendor":5.9,"cna":7.5},"ingestedAt":"2026-09-14T15:23:07.476Z","slug":"CVE-2026-80998","body":"## Overview\n\nA flaw was found in the Linux kernel's `bnxt` network driver. When processing a burst of packets, the driver may fail to notify the network device (ring the doorbell) if the Software UDP Segmentation Offload (SW USO) path exits prematurely. This oversight can lead to a transmit (TX) queue stall, rendering the network interface unresponsive and causing a Denial of Service (DoS) for network communications.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80998.json)\n\n**kernel: net: bnxt: ring the doorbell when SW USO exits early** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":204144,"id":"CVE-2026-80998","ts":1789490232408,"field":"cvss","old":"5.9","new":"5.5"},{"seq":202923,"id":"CVE-2026-80998","ts":1789403732966,"field":"cvss","old":"7.5","new":"5.9"},{"seq":202922,"id":"CVE-2026-80998","ts":1789403732966,"field":"severity","old":"high","new":"medium"},{"seq":183572,"id":"CVE-2026-80998","ts":1789356675936,"field":"cvss","old":"7.5","new":"5.9"},{"seq":183571,"id":"CVE-2026-80998","ts":1789356675936,"field":"severity","old":"high","new":"medium"},{"seq":153188,"id":"CVE-2026-80998","ts":1789285349469,"field":"cvss","old":null,"new":"7.5"},{"seq":153187,"id":"CVE-2026-80998","ts":1789285349469,"field":"severity","old":"none","new":"high"},{"seq":147744,"id":"CVE-2026-80998","ts":1789270212122,"field":"cvss","old":null,"new":"5.9"},{"seq":147743,"id":"CVE-2026-80998","ts":1789270212122,"field":"severity","old":"none","new":"medium"},{"seq":109486,"id":"CVE-2026-80998","ts":1789183732100,"field":"cvss","old":null,"new":"5.9"},{"seq":109485,"id":"CVE-2026-80998","ts":1789183732100,"field":"severity","old":"none","new":"medium"}]}