Database/Firmware, BMC & network fabric
Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/tc): Hardware flow-offload rules are programmed from a stale
Impact
Hardware flow-offload rules are programmed from a stale duplicate of the flow attribute, so when a neighbour update rewrites an encapsulation the driver pushes a freed object into the firmware flow-table command. The use-after-free lands in mlx5_cmd_set_fte, meaning freed kernel memory decides what steering rule the NIC installs - corrupted or attacker-influenced steering state on the device that forwards every tenant's traffic, plus node crashes.
Who can reach it
Driven by neighbour (ARP/ND) update events on the uplink, which any host on the adjacent L2 segment - including a tenant VM or container with its own IP on the fabric - can provoke by changing or churning its MAC-to-IP binding while tunnel-encapsulated TC flows are offloaded. Requires eswitch/switchdev mode with TC hardware offload and encapsulation rules in use, which is the normal configuration on a neocloud node running OVS offload.
What to do
Update to a kernel carrying the fix on your stream. Interim: disable TC hardware offload on the mlx5 uplink (ethtool -K <dev> hw-tc-offload off) or stop using tunnel-encap offload rules, and keep the fabric segment free of untrusted L2 neighbours.
References
Related entries
- Intel Xeon memory controller configuration (with SGX): An improper conditions check in Xeon memory controllerCVE-2024-23918 · Intel Xeon memory controller configuration (with SGX)High
- Linux guest kernel - hypervisor-injected int 0x80 on the 32-bit syscall path (SEV-SNP / SEV-ES, AMD-SB-3008): TheCVE-2024-25744 · Linux guest kernel - hypervisor-injected int 0x80 on the 32-bit syscall path (SEV-SNP / SEV-ES, AMD-SB-3008)High
- AMI AptioV BIOS (improper input validation, SMM): A local attacker overwrites arbitrary memory and executes code at SMMCVE-2024-33659 · AMI AptioV BIOS (improper input validation, SMM)High
- Dell SmartFabric OS10 (execution with unnecessary privileges): A low-privileged attacker escalates through an OS10CVE-2024-48013 · Dell SmartFabric OS10 (execution with unnecessary privileges)High
- Dell SmartFabric OS10 (default password): A default password in SmartFabric OS10 across 10.5.4.x through 10.6.0.xCVE-2024-49559 · Dell SmartFabric OS10 (default password)High
- Linux kernel mlx5_ib (InfiniBand/RoCE completion queue polling): mlx5_poll_one() compares the firmware's QP numberCVE-2025-22086 · Linux kernel mlx5_ib (InfiniBand/RoCE completion queue polling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.