Database/Firmware, BMC & network fabric
Linux kernel (drivers/vfio/pci/mlx5): Pages allocated for a device migration buffer are not freed when adding them to
Impact
Pages allocated for a device migration buffer are not freed when adding them to the scatter-gather table fails, leaking host memory on every failed attempt. On a fleet that live-migrates SR-IOV NIC functions between tenants, repeated failures bleed host RAM that never comes back.
Who can reach it
The mlx5 VFIO variant driver's migration buffer path, exercised by the host's migration control plane with a size influenced by the tenant device's state. Requires the SG-table add to fail, i.e. memory pressure. Conditional on ConnectX VFs being passed through with live migration enabled - common on ConnectX-backed neoclouds. Host-side path, not a direct tenant ioctl.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim control: monitor host memory across migration failures and drain nodes that show unexplained kernel memory growth.
References
Related entries
- Linux kernel (drivers/vfio/pci/mlx5): Migration and dirty-tracking state flags for an mlx5 VF were packed into sharedCVE-2026-64472 · Linux kernel (drivers/vfio/pci/mlx5)Medium
- Intel / Solidigm SSD, SSD DC and Optane SSD firmwareCVE-2021-33082 · Intel / Solidigm SSD, SSD DC and Optane SSD firmware - NVMe Sanitize (Block Erase) leaves prior data recoverableMedium
- AMD SEV firmware - use-after-free allowing a SINGLE_SOCKET guest to activate on the wrong socket (AMD-SB-3023): ACVE-2025-0031 · AMD SEV firmware - use-after-free allowing a SINGLE_SOCKET guest to activate on the wrong socket (AMD-SB-3023)Medium
- AMD CPU pipeline configuration - SEV-SNP guest stack pointer corruption: A write-what-where condition in CPU pipelineCVE-2025-29943 · AMD CPU pipeline configuration - SEV-SNP guest stack pointer corruptionMedium
- AMD SEV firmware - ASID range enforcement between SEV-ES and SEV-SNP guests: A malicious hypervisor can launch a SEV-ESCVE-2025-48517 · AMD SEV firmware - ASID range enforcement between SEV-ES and SEV-SNP guestsMedium
- Broadcom NetXtreme-E network adapter firmware: The lower-severity half of the same Positive Technologies NetXtreme-ECVE-2025-56548 · Broadcom NetXtreme-E network adapter firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.