Database/Firmware, BMC & network fabric
Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): The async firmware-command context can be freed while a
Impact
The async firmware-command context can be freed while a completion callback is still running, so the completion handler writes into a freed slab object from interrupt context. That is a kernel heap corruption primitive on a node shared with other tenants, and at minimum a panic that takes every workload on the box down with it.
Who can reach it
Needs code executing on the node that opens mlx5 async firmware-command channels and then tears them down while commands are in flight. The realistic holder is a tenant container with /dev/infiniband/uverbs* and DEVX enabled, or a VF driver instance inside a tenant VM; host-root paths (devlink reload, eswitch mode changes) reach the same race. Not reachable from the RDMA/IP fabric.
What to do
Boot a kernel carrying the mlx5_core fix (the kernel CNA published no fixed-version list for this ID - match the stable commits below against your distro's mlx5_core backport). Interim control: remove /dev/infiniband/* from untrusted containers and do not grant DEVX to tenant workloads.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): A userspace DEVX consumer can issue a firmware command opcodeCVE-2023-53340 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When a regular receive queue is reactivated after an AF_XDPCVE-2023-53394 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Adding a TC flower rule while the device is in NIC mode makesCVE-2023-54216 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): A command that waits on the busy command-queue semaphore startsCVE-2024-38556 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When a DMA mapping fails on the multi-packet transmit path, theCVE-2024-50001 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When an XDP program shrinks a multi-fragment receive bufferCVE-2026-43464 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.