Database/Firmware, BMC & network fabric
Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): A userspace DEVX consumer can issue a firmware command opcode
Impact
A userspace DEVX consumer can issue a firmware command opcode the driver does not track, and when that command fails the driver indexes its per-opcode failure-statistics array with the untracked opcode. The result is an out-of-bounds array access in shared driver state driven by a value the caller chose - memory corruption reachable from a tenant's RDMA device node, not just a crash.
Who can reach it
A tenant container holding /dev/infiniband/uverbs* with DEVX enabled (rdma-core mlx5dv DEVX general command) can send arbitrary firmware command opcodes and make them fail on purpose. No host root needed; the only precondition is that the tenant is allowed to open the mlx5 RDMA device and use DEVX, which is exactly what a bare RDMA/GPUDirect tenant is given.
What to do
Update to a patched kernel on your stream. Interim: drop /dev/infiniband/* from tenant containers that do not need verbs, or block DEVX for tenants (do not grant the RDMA device to untrusted workloads) until the node is rebooted onto a fixed kernel.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When a regular receive queue is reactivated after an AF_XDPCVE-2023-53394 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Adding a TC flower rule while the device is in NIC mode makesCVE-2023-54216 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): A command that waits on the busy command-queue semaphore startsCVE-2024-38556 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When a DMA mapping fails on the multi-packet transmit path, theCVE-2024-50001 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When an XDP program shrinks a multi-fragment receive bufferCVE-2026-43464 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Two CPUs write to the internal control send queue withoutCVE-2026-64210 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.