CVE-2026-52983: Linux Airoha Driver BQL Accounting Imbalance – Network Performance Risk
A flaw in the Linux kernel's Airoha network driver causes incorrect tracking of in-flight network packets across TX (transmit) queues. The driver counts packets sent through some queues but reports completions for all queues, creating an accounting mismatch that can degrade network performance or trigger scheduler anomalies. This is a kernel-level networking issue that affects systems running vulnerable Linux versions with Airoha hardware.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- —
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-24 / 2026-07-14
NVD description (verbatim)
In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix BQL imbalance in TX path Fix a possible BQL imbalance in airoha_dev_xmit(), where inflight packets are accounted only for the AIROHA_NUM_TX_RING netdev TX queues. The queue index is computed as: qid = skb_get_queue_mapping(skb) % ARRAY_SIZE(qdma->q_tx) txq = netdev_get_tx_queue(dev, qid); However, airoha_qdma_tx_napi_poll() accounts completions across all netdev TX queues (num_tx_queues), leading to inconsistent BQL accounting. Also reset all netdev TX queues in the ndo_stop callback.
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-52983 describes a Bandwidth Queue Limit (BQL) accounting imbalance in the Airoha driver's TX path. The airoha_dev_xmit() function computes a queue index using modulo arithmetic against AIROHA_NUM_TX_RING, then accounts inflight packets only for that subset of netdev TX queues. Conversely, airoha_qdma_tx_napi_poll() reports completions across all num_tx_queues, violating the BQL accounting invariant that inflight packets must be tracked symmetrically. The fix ensures consistent BQL state and adds proper TX queue reset in the ndo_stop callback.
Business impact
Systems relying on Airoha network interfaces may experience unpredictable network latency, packet scheduling anomalies, or DMA queue stalls under sustained high-throughput conditions. Affected deployments—particularly those running bandwidth-intensive workloads or edge computing platforms using Airoha silicon—risk degraded application performance and potential service availability issues. The impact is confined to packet transmission quality and scheduling; no data confidentiality or integrity loss occurs.
Affected systems
Linux kernel versions prior to the patch release, specifically systems equipped with Airoha network interface hardware and running affected kernel versions. Typical use cases include networking appliances, routers, and edge computing platforms that integrate Airoha PHY/MAC silicon. The scope is narrow but critical for affected device categories.
Exploitability
Exploitation requires no authentication, user interaction, or network-based triggering; however, practical impact manifests only under specific conditions: sustained high-throughput transmission workloads that trigger TX queue completion polling. Passive remote exploitation is not feasible. This is a quality/stability issue rather than a direct security vulnerability, though its effects on network reliability carry operational risk. No active exploit development is typically required to observe the issue—normal heavy TX load will trigger the BQL imbalance.
Remediation
Update the Linux kernel to a version incorporating the BQL accounting fix. Verify with your Linux distribution and hardware vendor for the specific kernel version or patch series that resolves this issue. For deployments unable to update immediately, monitor network performance metrics (BQL state, TX queue depth, latency variance) and consider traffic shaping to reduce TX queue strain until patches are deployed.
Patch guidance
Consult your Linux distribution's security advisory for the patch release date and version number specific to your kernel series (e.g., stable, LTS). Airoha hardware vendors (MediaTek, etc.) may also publish driver updates; verify against the vendor advisory whether a standalone driver patch is available prior to full kernel upgrade. Test in a non-production environment to confirm TX performance stabilization post-patch.
Detection guidance
Monitor kernel logs for TX scheduling anomalies, BQL warnings, or NAPI poll timeout events on Airoha interfaces. Use ethtool statistics to observe inconsistencies in TX queue depth, completion counts, or BQL state across queues. Compare netdev TX completions reported by airoha_qdma_tx_napi_poll() against inflight packet counts to identify the accounting gap. Sustained high throughput followed by latency spikes or packet drops is a telltale sign of BQL imbalance impact.
Why prioritize this
This CVE earns a HIGH CVSS score (7.5) due to its availability impact (denial of service via performance degradation) combined with low attack complexity and no authentication requirement. While the practical trigger requires specific TX load conditions, the asymmetry in BQL accounting means the issue will eventually manifest in production high-throughput scenarios. Organizations running Airoha-based network hardware under sustained load should prioritize kernel patching to avoid unpredictable performance incidents.
Risk score, explained
CVSS 3.1 score of 7.5 reflects an availability impact (A:H) that requires no authentication (PR:N), no user interaction (UI:N), and network-accessible scope (AV:N) with low complexity (AC:L). The HIGH severity classification appropriately captures the operational risk of network performance degradation on affected systems. The score does not account for scope limitation to Airoha-equipped devices; organizations without such hardware face zero risk.
Frequently asked questions
Does this vulnerability allow remote code execution or data theft?
No. CVE-2026-52983 is strictly a performance and availability issue affecting packet transmission scheduling. It does not compromise confidentiality, integrity, or enable code execution. The vulnerability manifests as network latency and throughput anomalies, not security breaches.
Will I be affected if I don't use Airoha network hardware?
No. This flaw is specific to the Airoha driver in the Linux kernel. Systems using other network interface vendors (Intel, Broadcom, Mellanox, etc.) are not affected, though they should maintain general kernel patching discipline.
What conditions trigger the BQL imbalance and its performance impact?
The accounting gap becomes visible under sustained, heavy TX workload—especially on systems that fill multiple TX queues concurrently. Normal or bursty traffic patterns may not reveal the issue. Edge networks, firewalls, and routers handling high packet rates are at higher risk of triggering observable performance problems.
Can I mitigate this without patching the kernel?
Temporary mitigations include reducing TX queue depth via ethtool, enabling traffic shaping to avoid saturation, or reducing network load. These are band-aids; the proper fix requires a kernel update. Monitor your systems closely and prioritize patching as part of routine maintenance.
This analysis is based on public vulnerability data as of the publication date. CVSS scores, affected versions, and patch release dates are provided by upstream sources and should be verified against official Linux distribution and Airoha hardware vendor advisories. This is not a substitute for independent security assessment. Organizations should validate patch applicability and test in non-production environments before deployment. SEC.co makes no warranty regarding completeness or accuracy of vulnerability intelligence and assumes no liability for operational decisions made in reliance upon this analysis. Source: NVD (public-domain), retrieved 2026-07-31. Analysis generated by SEC.co (claude-haiku-4-5).
Affected vendors
Related vulnerabilities
- CVE-2026-0270HIGHCortex XSOAR Path Traversal on Linux — Exploit Requirements & Patching Guide
- CVE-2026-0271HIGHPalo Alto Networks Prisma Access Agent Linux Privilege Escalation
- CVE-2026-10001HIGHChrome Sandbox Escape via PerformanceManager Use-After-Free
- CVE-2026-10002HIGHGoogle Chrome PDFium Use-After-Free Vulnerability (CVSS 8.8)
- CVE-2026-10003HIGHChrome Use-After-Free Code Execution Vulnerability Analysis
- CVE-2026-10006HIGHChrome WebAudio Race Condition Remote Code Execution
- CVE-2026-10007HIGHChrome Use-After-Free in SVG Arbitrary Code Execution (CVSS 8.8)
- CVE-2026-10009HIGHChrome Skia Integer Overflow Sandbox Escape – Patch Guidance