Database/Firmware, BMC & network fabric
Linux kernel mlx5_core eswitch vport representors / IPsec FS: During driver unload the vport representor private struct
Impact
During driver unload the vport representor private struct is freed before unregister_netdev runs, so the kernel walks freed representor state across every VF on the box. Vport representors are the per-tenant hooks in switchdev mode; a use-after-free walking all of them on a shared host is a host-kernel corruption reachable through ordinary driver lifecycle events.
Who can reach it
Local - triggered on mlx5 driver unload/reload on a switchdev SR-IOV host. Reachable by anyone who can induce a driver reload (operator action, firmware reset flow, or a fault path an attacker provokes).
What to do
Upgrade the host kernel to 6.13 or a stable backport (6.6.70, 6.12.9). Rolling reboot. Until then, avoid mlx5 driver unload/reload on live switchdev hosts - use full node reboots instead of in-place driver restarts.
References
Related entries
- Linux kernel RDMA core (ib_uverbs post_send / post_recv command parsing): The uverbs write path multiplied two fullyCVE-2024-57890 · Linux kernel RDMA core (ib_uverbs post_send / post_recv command parsing)High
- GRUB2 (squashfs): Integer overflow in the squash4 filesystem module leading to out-of-bounds write and possible SecureCVE-2025-0678 · GRUB2 (squashfs)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/steering/hws): A matcher that fails to disconnect is reinsertedCVE-2025-21751 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/steering/hws)High
- Linux kernel mlx5_core eswitch vport QoS scheduling: When enabling per-vport QoS fails, the scheduling node is leakedCVE-2025-21882 · Linux kernel mlx5_core eswitch vport QoS schedulingHigh
- Linux x86/microcode/AMD - out-of-bounds on CPU-less NUMA nodes: The AMD microcode loader iterated every NUMA nodeCVE-2025-21991 · Linux x86/microcode/AMD - out-of-bounds on CPU-less NUMA nodesHigh
- Linux kernel RDMA core (hw_counters sysfs exposure across network namespaces): RDMA hardware counter sysfs attributesCVE-2025-22089 · Linux kernel RDMA core (hw_counters sysfs exposure across network namespaces)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.