Database/Kernel, userspace & hypervisor
Linux kernel mlx5_core representor TC path + net/sched tc extension: The TC_SKB_EXT skb extension is not zeroed
Impact
The TC_SKB_EXT skb extension is not zeroed on allocation and mlx5's representor restore path never initialized the newer fields, so Open vSwitch reads uninitialized kernel memory as a boolean. This leaks host kernel memory contents into the OVS datapath - and it is triggered remotely, by sending packets that miss hardware offload. On a switchdev host running OVS over ConnectX, that is remote kernel-memory disclosure into the software datapath.
Who can reach it
Remote, unauthenticated: send traffic crafted to miss the hardware offload path on an mlx5 switchdev host running OVS.
What to do
Upgrade the host kernel to 5.13 or a stable backport (5.10.42, 5.12.9). Rolling reboot. Note NVD scores this 5.5 while the kernel CNA scores it 8.6 - if you triage from NVD feeds you will under-prioritize it.
References
Related entries
- Linux kernel (net/tls): When a BPF socket policy shrinks the plaintext after the ciphertext length was computed, kTLSCVE-2025-38608 · Linux kernel (net/tls)High
- Linux kernel libceph: truncated monitor reply decodes stale bytes from the reused bufferCVE-2026-68433 · Linux kernel libceph (MON_GET_VERSION_REPLY decode bound)High
- sudo: intercept policy checks skipped for execveat, letting allowed users run denied commandsCVE-2026-82474 · sudo (ptrace-based intercept mode, execveat/fexecve path)High
- Linux kernel (arch/x86/kvm/svm): Hardware ignores the low five bits of CR3 when loading PDPTEs, but KVM's nested SVMCVE-2024-50115 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel arm_ffa: unvalidated notification layout drives out-of-bounds read of the shared RX bufferCVE-2026-64081 · Linux kernel arm_ffa (Arm FF-A framework notification parsing)High
- Linux kernel (arch/x86/kvm): A nested guest can put an out-of-range virtual-processor ID into an enlightened VMCS andCVE-2026-64247 · Linux kernel (arch/x86/kvm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.