Database/Kernel, userspace & hypervisor
Linux kernel mlx5_core TC connection tracking offload: Updating a connection-tracking entry allocates a replacement
Impact
Updating a connection-tracking entry allocates a replacement modify-header context; if that allocation fails - which it does once you exceed the firmware's maximum, a state an attacker can drive by opening many connections - the error pointer is stored and later dereferenced on free, panicking the kernel, and the old context is leaked. Remote traffic volume alone is enough to reach it on a node doing hardware conntrack offload.
Who can reach it
Remote, unauthenticated: open enough tracked connections through an mlx5 host doing CT offload to exhaust the firmware's modify-header capacity.
What to do
Upgrade the host kernel to 6.11 or a stable backport (6.6.45, 6.10.4). Rolling reboot. Interim: disable hardware connection-tracking offload on the mlx5 interfaces or cap conntrack table size, both live config changes.
References
Related entries
- Linux kernel mlx5_core RX datapath (SHAMPO): SHAMPO can deliver completion entries with zero consumed stridesCVE-2024-44970 · Linux kernel mlx5_core RX datapath (SHAMPO)Critical
- Linux kernel mlx5_core RX datapath (SHAMPO / HW-GRO): A remote sender can make the mlx5 receive path release a SHAMPOCVE-2024-46717 · Linux kernel mlx5_core RX datapath (SHAMPO / HW-GRO)Critical
- Linux kernel SMC-R/SMC-D (CLC proposal parsing, smcd_v2_ext_offset): The SMC server trusted an offset field takenCVE-2024-47408 · Linux kernel SMC-R/SMC-D (CLC proposal parsing, smcd_v2_ext_offset)Critical
- Linux kernel RTRS client (rtrs-clt init_conns connection-id bound): When connection setup fails partway through, theCVE-2024-47695 · Linux kernel RTRS client (rtrs-clt init_conns connection-id bound)Critical
- Linux kernel SMC-R/SMC-D (CLC proposal parsing, v2_ext_offset / eid_cnt / ism_gid_cnt): The same unvalidated-offsetCVE-2024-49568 · Linux kernel SMC-R/SMC-D (CLC proposal parsing, v2_ext_offset / eid_cnt / ism_gid_cnt)Critical
- Linux kernel mlx5_core kTLS TX offload: The kTLS TX path mixes get_page() and page_ref_inc() when acquiring referencesCVE-2024-53138 · Linux kernel mlx5_core kTLS TX offloadCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.