Database/Firmware, BMC & network fabric
Linux kernel mlxsw (Spectrum switch ASIC ACL TCAM): On Spectrum-2 and newer, firmware reports more than 16 ACLs per
Impact
On Spectrum-2 and newer, firmware reports more than 16 ACLs per group but the driver's register layout was never widened, so putting more than 16 ACLs in a group corrupts the kernel stack and panics the switch. Triggered by adding tc filters with decreasing priority in alternating order - a shape that ordinary policy automation produces. Relevant to anyone running Linux-based switch control on Spectrum silicon.
Who can reach it
Local on the switch with network-configuration privilege - an operator or automation system installing tc filters. Not remotely reachable.
What to do
Upgrade the switch's kernel to 6.8 or a stable backport (5.10.209, 5.15.148, 6.1.79, 6.6.14, 6.7.2). On a Cumulus/NVOS switch that means an OS image upgrade and a switch reload - a fabric rolling window. Interim: constrain your ACL automation so a single group never exceeds 16 ACLs.
References
Related entries
- Linux kernel (drivers/infiniband/hw/hfi1): An off-by-one in the SDMA descriptor accounting lets the descriptor array inCVE-2024-26766 · Linux kernel (drivers/infiniband/hw/hfi1)High
- AMI AptioV UEFI BIOS (SmmComputrace DXE module): The SmmComputrace DXE module leaks stack and global memory to a localCVE-2024-33656 · AMI AptioV UEFI BIOS (SmmComputrace DXE module)High
- AMI AptioV UEFI BIOS (SMM modules): An SMM vulnerability letting a privileged local attacker execute arbitrary codeCVE-2024-33657 · AMI AptioV UEFI BIOS (SMM modules)High
- AMI AptioV BIOS (memory buffer restriction failure): Local privilege escalation and potentially arbitrary codeCVE-2024-33658 · AMI AptioV BIOS (memory buffer restriction failure)High
- Linux kernel (drivers/infiniband/hw/hns): The completion-queue refcount is not held under a lock, so a CQ asynchronousCVE-2024-38545 · Linux kernel (drivers/infiniband/hw/hns)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): A command that waits on the busy command-queue semaphore startsCVE-2024-38556 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.