CVE-2025-21960: eth: bnxt: do not update checksum in bnxt_xdp_build_skb()
In the Linux kernel, the following vulnerability has been resolved:
eth: bnxt: do not update checksum in bnxt_xdp_build_skb()
The bnxt_rx_pkt() updates ip_summed value at the end if checksum offload
is enabled.
When the XDP-MB program is attached and it returns XDP_PASS, the
bnxt_xdp_build_skb() is called to update skb_shared_info.
The main purpose of bnxt_xdp_build_skb() is to update skb_shared_info,
but it updates ip_summed value too if checksum offload is enabled.
This is actually duplicate work.
When the bnxt_rx_pkt() updates ip_summed value, it checks if ip_summed
is CHECKSUM_NONE or not.
It means that ip_summed should be CHECKSUM_NONE at this moment.
But ip_summed may already be updated to CHECKSUM_UNNECESSARY in the
XDP-MB-PASS path.
So the by skb_checksum_none_assert() WARNS about it.
This is duplicate work and updating ip_summed in the
bnxt_xdp_build_skb() is not needed.
Splat looks like:
WARNING: CPU: 3 PID: 5782 at ./include/linux/skbuff.h:5155 bnxt_rx_pkt+0x479b/0x7610 [bnxt_en]
Modules linked in: bnxt_re bnxt_en rdma_ucm rdma_cm iw_cm ib_cm ib_uverbs veth xt_nat xt_tcpudp xt_conntrack nft_chain_nat xt_MASQUERADE nf_]
CPU: 3 UID: 0 PID: 5782 Comm: socat Tainted: G W 6.14.0-rc4+ #27
Tainted: [W]=WARN
Hardware name: ASUS System Product Name/PRIME Z690-P D4, BIOS 0603 11/01/2021
RIP: 0010:bnxt_rx_pkt+0x479b/0x7610 [bnxt_en]
Code: 54 24 0c 4c 89 f1 4c 89 ff c1 ea 1f ff d3 0f 1f 00 49 89 c6 48 85 c0 0f 84 4c e5 ff ff 48 89 c7 e8 ca 3d a0 c8 e9 8f f4 ff ff <0f> 0b f
RSP: 0018:ffff88881ba09928 EFLAGS: 00010202
RAX: 0000000000000000 RBX: 00000000c7590303 RCX: 0000000000000000
RDX: 1ffff1104e7d1610 RSI: 0000000000000001 RDI: ffff8881c91300b8
RBP: ffff88881ba09b28 R08: ffff888273e8b0d0 R09: ffff888273e8b070
R10: ffff888273e8b010 R11: ffff888278b0f000 R12: ffff888273e8b080
R13: ffff8881c9130e00 R14: ffff8881505d3800 R15: ffff888273e8b000
FS: 00007f5a2e7be080(0000) GS:ffff88881ba00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fff2e708ff8 CR3: 000000013e3b0000 CR4: 00000000007506f0
PKRU: 55555554
Call Trace:
<IRQ>
? __warn+0xcd/0x2f0
? bnxt_rx_pkt+0x479b/0x7610
? report_bug+0x326/0x3c0
? handle_bug+0x53/0xa0
? exc_invalid_op+0x14/0x50
? asm_exc_invalid_op+0x16/0x20
? bnxt_rx_pkt+0x479b/0x7610
? bnxt_rx_pkt+0x3e41/0x7610
? __pfx_bnxt_rx_pkt+0x10/0x10
? napi_complete_done+0x2cf/0x7d0
__bnxt_poll_work+0x4e8/0x1220
? __pfx___bnxt_poll_work+0x10/0x10
? __pfx_mark_lock.part.0+0x10/0x10
bnxt_poll_p5+0x36a/0xfa0
? __pfx_bnxt_poll_p5+0x10/0x10
__napi_poll.constprop.0+0xa0/0x440
net_rx_action+0x899/0xd00
...
Following ping.py patch adds xdp-mb-pass case. so ping.py is going
to be able to reproduce this issue.
Security readout for executives and security teams
Plain-English summary
A Linux Broadcom network-driver flaw can mishandle packet checksum state when an XDP multi-buffer program allows traffic through. This triggers a kernel warning and is rated as a high availability risk. It matters primarily to systems using the bnxt driver with this specialized XDP configuration, not every Linux host.
Executive priority
Treat as high priority for confirmed bnxt_en systems using XDP multi-buffer packet processing, especially availability-sensitive infrastructure. For other Linux systems, first validate the required driver and XDP configuration before escalating emergency work. No active exploitation is established by the supplied sources.
Technical view
In bnxt_en, bnxt_xdp_build_skb() redundantly changes skb ip_summed during the XDP-MB XDP_PASS path. bnxt_rx_pkt() later expects CHECKSUM_NONE before applying checksum-offload state, causing skb_checksum_none_assert() to warn. The cited stable-kernel commits remove the duplicate update. The supplied CVSS is 7.5, reflecting network-reachable availability impact without confidentiality or integrity impact.
Likely exposure
Exposure requires an affected Linux kernel, the Broadcom bnxt_en network driver, checksum offload, and an attached XDP multi-buffer program returning XDP_PASS. Hosts without that combination are unlikely to encounter this specific path. The supplied version data is ambiguous, so distribution package status and vendor advisories should determine exposure.
Exploitation context
The bundle provides a reproducible test-path description but no evidence of malicious exploitation. CVE-2025-21960 is not listed as KEV in the supplied data. Network reachability is represented in the CVSS vector, but the sources do not establish practical remote exploitation conditions, widespread attacks, or a public weaponized exploit.
Researcher notes
The defect is a duplicated skb checksum-state update in the XDP-MB pass path, producing an assertion warning when bnxt_rx_pkt() performs its expected update. The source bundle lists several affected and commit-like version values without clear range semantics. Validate fixes using distribution backport records rather than kernel version comparison alone.
Mitigation direction
Apply a supported kernel update containing the applicable cited stable-kernel fix.
Use distribution or hardware-vendor advisories to identify the correct fixed package.
Prioritize affected hosts performing XDP-based packet processing with bnxt_en interfaces.
If updates are unavailable, request vendor-approved temporary mitigation guidance.
Validation and detection
Inventory kernel versions and distribution package revisions on systems using bnxt_en.
Confirm whether XDP multi-buffer programs are attached to bnxt_en interfaces.
Determine whether checksum offload is enabled on those interfaces.
Review kernel logs for bnxt_rx_pkt or skb_checksum_none_assert warnings.
Verify the installed update incorporates the applicable stable-kernel fix.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-21960 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
7Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.