Database/Firmware, BMC & network fabric
Linux kernel mlx5_core eswitch ingress ACL: The eswitch ingress ACL - the table that enforces per-VF ingress policy
Impact
The eswitch ingress ACL - the table that enforces per-VF ingress policy - is only created when vport metadata match or prio tag is on. Turn vport metadata match off via devlink and bring up an active-backup LAG, and the driver panics on a missing ingress ACL. Beyond the crash, this is a config in which the VF ingress enforcement structure is simply absent when the driver expects it.
Who can reach it
Requires an administrator to have set esw_port_metadata=false via devlink and to be running active-backup LAG. Not tenant-triggered, but it is a realistic operator configuration on bonded ConnectX hosts.
What to do
Upgrade the host kernel to 6.10 or a stable backport (6.1.98, 6.6.39, 6.9.9). Rolling reboot. Immediate config-level mitigation: keep esw_port_metadata at its default (true) on LAG hosts - a devlink change, no reboot.
References
Related entries
- Juniper Junos OS (httpd / J-Web on QFX5120, EX, SRX, MX): Crafted HTTP requests to the web management process drive CPUCVE-2025-21601 · Juniper Junos OS (httpd / J-Web on QFX5120, EX, SRX, MX)Unscored
- Juniper Junos OS / Junos OS Evolved (rpd, BGP UPDATE): A crafted BGP UPDATE crashes the routing protocol daemon. In aCVE-2025-21602 · Juniper Junos OS / Junos OS Evolved (rpd, BGP UPDATE)Unscored
- EDK II OvmfPkg (X86QemuLoadImageLib, QemuLoadKernelImage direct-boot path): With Secure Boot on, a kernelCVE-2025-2296 · EDK II OvmfPkg (X86QemuLoadImageLib, QemuLoadKernelImage direct-boot path)Unscored
- Dell Enterprise SONiC (sensitive information in log files): Sensitive information is written into log filesCVE-2025-23374 · Dell Enterprise SONiC (sensitive information in log files)Unscored
- Arista EOS (ingress ACL enforcement on ethernet/LAG): With IPv4 ingress, MAC ingress, or IPv6 standard ingress ACLsCVE-2025-2826 · Arista EOS (ingress ACL enforcement on ethernet/LAG)Unscored
- Linux kernel mlxbf-bootctl (BlueField secure boot fuse state): The BlueField boot-control driver mishandles the sysfsCVE-2025-37866 · Linux kernel mlxbf-bootctl (BlueField secure boot fuse state)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.