Database/Firmware, BMC & network fabric
Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/steering/hws): A matcher that fails to disconnect is reinserted
Impact
A matcher that fails to disconnect is reinserted into the shared hardware-steering matcher list and then freed by the caller, leaving a dangling entry in state that serves every tenant's offloaded flow rules on that NIC. The result is a use-after-free and node crash, and before the crash the steering graph can be left mis-wired so packets are evaluated against the wrong rule set.
Who can reach it
The HWS matcher list is shared state sitting behind tenant-visible flow offload - the tc/OVS rules programmed for VF representors on behalf of tenant VMs. Triggering the bad path requires a firmware command failure during matcher disconnect, which sustained rule churn or steering-resource exhaustion from a tenant can provoke. Requires mlx5 hardware steering with switchdev/eswitch offload enabled. Not reachable directly from the fabric.
What to do
Boot a kernel carrying the HWS disconnect error-flow fix (stable commits below; no fixed-version list published for this ID). Interim controls: cap the number of offloaded flow rules per tenant representor, and prefer software steering (DMFS/SMFS) over HWS on nodes where tenants drive rule installation.
References
Related entries
- Linux kernel mlx5_core eswitch vport QoS scheduling: When enabling per-vport QoS fails, the scheduling node is leakedCVE-2025-21882 · Linux kernel mlx5_core eswitch vport QoS schedulingHigh
- Linux x86/microcode/AMD - out-of-bounds on CPU-less NUMA nodes: The AMD microcode loader iterated every NUMA nodeCVE-2025-21991 · Linux x86/microcode/AMD - out-of-bounds on CPU-less NUMA nodesHigh
- Linux kernel RDMA core (hw_counters sysfs exposure across network namespaces): RDMA hardware counter sysfs attributesCVE-2025-22089 · Linux kernel RDMA core (hw_counters sysfs exposure across network namespaces)High
- Dell SmartFabric OS10 (command injection with elevated privileges): Local low-privilege attacker executes commandsCVE-2025-22472 · Dell SmartFabric OS10 (command injection with elevated privileges)High
- Dell SmartFabric OS10 (command injection, local): A low-privileged local attacker achieves code execution on the switchCVE-2025-22473 · Dell SmartFabric OS10 (command injection, local)High
- AMI AptioV BIOS (out-of-bounds write): Second local out-of-bounds write in the same AptioV advisoryCVE-2025-22831 · AMI AptioV BIOS (out-of-bounds write)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.