Database/Firmware, BMC & network fabric
Linux kernel mlx5_core eswitch offloads (termination tables): Adding a multi-destination eswitch rule that partially
Impact
Adding a multi-destination eswitch rule that partially fails leaves a stale termination-table pointer, and releasing the rule triggers a use-after-free in the eswitch - the exact subsystem that enforces which VF sees which traffic. Corruption here is a plausible route to host kernel control from a workload that only has network-namespace privilege.
Who can reach it
A local user who can add and delete tc flower rules with CAP_NET_ADMIN - obtainable in an unprivileged user namespace (unshare -Urn), so reachable from inside many container runtimes, not just from host root.
What to do
Upgrade the host kernel to 6.1 or a stable backport (5.4.226, 5.10.158, 5.15.82, 6.0.12). Rolling reboot of the fleet. Interim: disable unprivileged user namespaces (kernel.unprivileged_userns_clone=0 / user.max_user_namespaces=0) where your container runtime does not need them - a sysctl config change, no reboot.
References
Related entries
- Linux kernel (drivers/infiniband/hw/hfi1): The driver drops the last reference on a process's memory-descriptorCVE-2022-49076 · Linux kernel (drivers/infiniband/hw/hfi1)High
- Linux kernel (drivers/infiniband/hw/irdma): Use-after-free on completion-queue teardown. The driver frees the CQCVE-2022-50137 · Linux kernel (drivers/infiniband/hw/irdma)High
- Linux kernel (drivers/infiniband/sw/rxe): A tenant gets a double free in the kernel heap through a failed memoryCVE-2022-50543 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): The async firmware-command context can be freed while aCVE-2022-50726 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- TPM 2.0 reference implementation: Out-of-bounds write in `CryptParameterDecryption`CVE-2023-1017 · TPM 2.0 reference implementationHigh
- AMD Secure Processor - TOCTOU race: A time-of-check-to-time-of-use race in the ASP lets an attacker swap a valueCVE-2023-20548 · AMD Secure Processor - TOCTOU raceHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.