In the Linux kernel, the following vulnerability has been resolved:
eth: bnxt: fix out-of-range access of vnic_info array
The bnxtqueue{start | stop}() access vnicinfo as much as allocated, which indicates bp->nrvnics. So, it should not reach bp->vnicinfo[bp->nrvnics].
[
{
"signature_type": "Function",
"id": "CVE-2025-22112-0e545ace",
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e1724f07693439deaa413ebc2a2640325cf247f5",
"target": {
"function": "bnxt_queue_start",
"file": "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
},
"digest": {
"function_hash": "13651780057064963942207782169840736735",
"length": 1417.0
}
},
{
"signature_type": "Function",
"id": "CVE-2025-22112-24b06d78",
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b1e081d331ab3a0dea25425f2b6ddeb365fc9d22",
"target": {
"function": "bnxt_queue_stop",
"file": "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
},
"digest": {
"function_hash": "259160631165988894687648941551568119516",
"length": 679.0
}
},
{
"signature_type": "Line",
"id": "CVE-2025-22112-4d11927c",
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b1e081d331ab3a0dea25425f2b6ddeb365fc9d22",
"target": {
"file": "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
},
"digest": {
"line_hashes": [
"156861833194659468498233431030941751620",
"325398718022585984593347205947406615215",
"97588426983329120125377880829447199451",
"135592898616263606376853261986498817651",
"158921731867535522766575145182514750989",
"245323555594001218569156997752845564582",
"87580992181686914079422448148767625755",
"79720164196128501898014611383442784045"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"id": "CVE-2025-22112-a9deec64",
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@919f9f497dbcee75d487400e8f9815b74a6a37df",
"target": {
"function": "bnxt_queue_stop",
"file": "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
},
"digest": {
"function_hash": "259160631165988894687648941551568119516",
"length": 679.0
}
},
{
"signature_type": "Line",
"id": "CVE-2025-22112-bc7a0eaf",
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@919f9f497dbcee75d487400e8f9815b74a6a37df",
"target": {
"file": "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
},
"digest": {
"line_hashes": [
"156861833194659468498233431030941751620",
"325398718022585984593347205947406615215",
"97588426983329120125377880829447199451",
"135592898616263606376853261986498817651",
"158921731867535522766575145182514750989",
"245323555594001218569156997752845564582",
"87580992181686914079422448148767625755",
"79720164196128501898014611383442784045"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"id": "CVE-2025-22112-d155f789",
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b1e081d331ab3a0dea25425f2b6ddeb365fc9d22",
"target": {
"function": "bnxt_queue_start",
"file": "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
},
"digest": {
"function_hash": "13651780057064963942207782169840736735",
"length": 1417.0
}
},
{
"signature_type": "Function",
"id": "CVE-2025-22112-d71963f8",
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e1724f07693439deaa413ebc2a2640325cf247f5",
"target": {
"function": "bnxt_queue_stop",
"file": "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
},
"digest": {
"function_hash": "259160631165988894687648941551568119516",
"length": 679.0
}
},
{
"signature_type": "Function",
"id": "CVE-2025-22112-eaede28e",
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@919f9f497dbcee75d487400e8f9815b74a6a37df",
"target": {
"function": "bnxt_queue_start",
"file": "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
},
"digest": {
"function_hash": "13651780057064963942207782169840736735",
"length": 1417.0
}
},
{
"signature_type": "Line",
"id": "CVE-2025-22112-f45aa67f",
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e1724f07693439deaa413ebc2a2640325cf247f5",
"target": {
"file": "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
},
"digest": {
"line_hashes": [
"156861833194659468498233431030941751620",
"325398718022585984593347205947406615215",
"97588426983329120125377880829447199451",
"135592898616263606376853261986498817651",
"158921731867535522766575145182514750989",
"245323555594001218569156997752845564582",
"87580992181686914079422448148767625755",
"79720164196128501898014611383442784045"
],
"threshold": 0.9
}
}
]