Database/Firmware, BMC & network fabric
Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel): The IPsec offload worker does not check the xfrm
Impact
The IPsec offload worker does not check the xfrm state's lifecycle before expiring it, so an SA that is already dead gets deleted a second time and the kernel dereferences poison list pointers. On a node where the fabric encryption terminates, this is a general protection fault that panics the host and takes every tenant on it offline.
Who can reach it
Requires mlx5 IPsec packet/full offload to be configured on the node (fabric-level encryption). The racing worker fires on SA soft/hard packet-count limits, so the timing window is opened by traffic volume across the tunnel - a fabric peer pushing traffic influences when it triggers - while SA teardown comes from the local IKE daemon. This is not a tenant-controlled primitive, but it is a peer-influenced panic on shared infrastructure.
What to do
Boot a kernel with the mlx5e IPsec state-check fix (stable commits below; no fixed-version list published for this ID). Interim control: if IPsec offload is not actually needed on a given node, run the fabric without mlx5 IPsec offload configured - the vulnerable worker is not scheduled when no offloaded SAs exist.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel): All IPsec offload objects on a physical function shareCVE-2026-23441 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel)Medium
- Intel PCIe Switch firmware package and LED mode toggle tool before version MR4_1.0b1: Improper access controlCVE-2025-24323 · Intel PCIe Switch firmware package and LED mode toggle tool before version MR4_1.0b1Medium
- Intel Ethernet Network Adapter E810 (100GbE) firmware: Out-of-bounds read in 100GbE E810 firmware reachableCVE-2025-32003 · Intel Ethernet Network Adapter E810 (100GbE) firmwareMedium
- Dell SmartFabric OS10 (XML external entity): XXE in SmartFabric OS10 before 10.6.0.5, reachable remotelyCVE-2025-36608 · Dell SmartFabric OS10 (XML external entity)Medium
- Linux kernel (drivers/infiniband/core): Bursts of network neighbour updates crash the node. Each event re-initializes aCVE-2025-37772 · Linux kernel (drivers/infiniband/core)Medium
- Linux kernel RDS over InfiniBand (FRMR registration before connection establishment): An RDS sendmsg carryingCVE-2026-31425 · Linux kernel RDS over InfiniBand (FRMR registration before connection establishment)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.