{"id":"CVE-2026-93830","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: xgmac2: disable RBUE in default RX interrupt mask\n\nEnabling the RX Buffer Unavailable (RBUE) interrupt is counterproductive\nand can trigger a MAC interrupt…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: xgmac2: disable RBUE in default RX interrupt mask\n\nEnabling the RX Buffer Unavailable (RBUE) interrupt is counterproductive\nand can trigger a MAC interrupt…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0b1a5d3647ce07c27a9fffefc11a8cbf7d7b25ce","Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 87e2826ed2058747ddf014c082569a46bfadd96b","Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d3265c19b35d036bba327b36b5366bee76b0157c","Linux < 6.12.111","Linux < 6.18.53","Linux (all versions)"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T17:17:16.740","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93830","references":[{"url":"https://git.kernel.org/stable/c/0b1a5d3647ce07c27a9fffefc11a8cbf7d7b25ce","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87e2826ed2058747ddf014c082569a46bfadd96b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3265c19b35d036bba327b36b5366bee76b0157c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T16:47:15.889Z","slug":"CVE-2026-93830","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: xgmac2: disable RBUE in default RX interrupt mask\n\nEnabling the RX Buffer Unavailable (RBUE) interrupt is counterproductive\nand can trigger a MAC interrupt storm under heavy RX pressure. When the\nDMA runs out of RX descriptors it fires RBUE continuously until software\nrefills the ring.\n\nHowever, RBUE is redundant: the normal RX completion interrupt (RIE)\nalready triggers NAPI, which processes completed descriptors and refills\nthe ring, causing the DMA to resume. The RBUE handler itself only sets\nhandle_rx - the same outcome as RIE.\n\nOn Agilex5 under heavy RX pressure, the MAC interrupt (which includes\nRBUE) was observed firing 1,821,811,555 times against only 2,618,627\nactual RX completions - a ~695x ratio - confirming the severity of the\nstorm.\n\nRBUE does not provide OOM recovery. If page_pool is exhausted,\nstmmac_rx_refill() cannot advance the DMA tail pointer, the DMA stays\nsuspended, and RBUE fires again on the next NAPI completion - a storm\nwith no forward progress. This patch trades that storm for a clean\nstall with the same RX outcome. Proper OOM recovery is a pre-existing\ngap outside the scope of this fix.\n\nNote: as a consequence of disabling RBUE, the rx_buf_unav_irq ethtool\ncounter will always read 0 on XGMAC2 devices. This behaviour is already\ninconsistent across DWMAC core versions.\n\nRemove RBUE from XGMAC_DMA_INT_DEFAULT_EN and XGMAC_DMA_INT_DEFAULT_RX\nto prevent the interrupt storm while keeping normal RX handling intact.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}