Database/Firmware, BMC & network fabric
Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): The transmit health reporter's dump callback casts its
Impact
The transmit health reporter's dump callback casts its argument to the wrong structure type on the TX-timeout recovery path. The type confusion walks bogus pointers, overflows the kernel stack past the guard page and panics the machine - a single stuck transmit queue turns into a fatal crash that takes every tenant on the node with it.
Who can reach it
The trigger is a TX timeout on an mlx5 queue, which is reachable through fabric-level conditions (severe congestion, link flap, a queue wedged by a heavy neighbour) rather than through a tenant device node. No privileges are required to be the workload that causes the stalled queue, but there is no direct attacker-controlled input - treat this as a shared-node availability and memory-safety defect, not a targeted exploit path.
What to do
Update to a patched kernel on your stream. There is no configuration workaround short of disabling the devlink TX health reporter's dump on affected kernels; plan node reboots.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): After a transmit-queue error triggers driver recovery, theCVE-2026-43466 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): Every time an XDP_TX transmit fails because the XDP sendCVE-2026-53229 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)High
- Linux kernel Soft-RoCE completer (rdma_rxe, invalid lkey handling in atomic operations): The local key is the RDMACVE-2021-47076 · Linux kernel Soft-RoCE completer (rdma_rxe, invalid lkey handling in atomic operations)Medium
- Linux kernel RDMA core + mlx5_ib (ib_uverbs_ex_create_flow, flow steering rule creation): The port number a tenantCVE-2021-47265 · Linux kernel RDMA core + mlx5_ib (ib_uverbs_ex_create_flow, flow steering rule creation)Medium
- Intel processors (branch history injection): BHI / Spectre-BHB: even with eIBRS enabled, the branch history buffer isCVE-2022-0001 · Intel processors (branch history injection)Medium
- Intel processors (intra-mode branch target injection): The intra-mode sibling of BHI: branch predictor state is sharedCVE-2022-0002 · Intel processors (intra-mode branch target injection)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.