Database/Kernel, userspace & hypervisor
Linux kernel mlx5_core RX datapath (SHAMPO / HW-GRO): A remote sender can make the mlx5 receive path release a SHAMPO
Impact
A remote sender can make the mlx5 receive path release a SHAMPO header page while it is still in use, giving a double release and DMA into freed memory. This runs in NAPI softirq on every inbound frame, before any socket lookup or credential check - so an unauthenticated peer anywhere that can route packets to the node corrupts host kernel memory on the primary datacenter NIC. Note that NVD rates this 5.5 while the assigning kernel.org CNA rates it 9.8; the CNA score is the one that reflects reachability.
Who can reach it
Unauthenticated remote attacker able to send network traffic to a node running mlx5 with HW-GRO/SHAMPO enabled. No account, no VM, no adjacency needed.
What to do
Upgrade the host kernel to 6.11 or a stable backport (6.1.109, 6.6.50, 6.10.9). Rolling reboot of every ConnectX/BlueField host. Immediate mitigation without reboot: disable HW-GRO on the mlx5 interfaces (ethtool -K <dev> rx-gro-hw off), which takes the SHAMPO path out of service at some throughput cost.
References
Related entries
- Linux kernel SMC-R/SMC-D (CLC proposal parsing, smcd_v2_ext_offset): The SMC server trusted an offset field takenCVE-2024-47408 · Linux kernel SMC-R/SMC-D (CLC proposal parsing, smcd_v2_ext_offset)Critical
- Linux kernel RTRS client (rtrs-clt init_conns connection-id bound): When connection setup fails partway through, theCVE-2024-47695 · Linux kernel RTRS client (rtrs-clt init_conns connection-id bound)Critical
- Linux kernel SMC-R/SMC-D (CLC proposal parsing, v2_ext_offset / eid_cnt / ism_gid_cnt): The same unvalidated-offsetCVE-2024-49568 · Linux kernel SMC-R/SMC-D (CLC proposal parsing, v2_ext_offset / eid_cnt / ism_gid_cnt)Critical
- Linux kernel mlx5_core kTLS TX offload: The kTLS TX path mixes get_page() and page_ref_inc() when acquiring referencesCVE-2024-53138 · Linux kernel mlx5_core kTLS TX offloadCritical
- Linux kernel (net/smc): The server-side listen worker frees a connection outside the socket lock, so smc_conn_free()CVE-2024-56640 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): A link-down work item can be queued before the link group is freed but run after, so the workerCVE-2024-56718 · Linux kernel (net/smc)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.