Database/Firmware, BMC & network fabric
Linux kernel mlx5_core eswitch vport QoS scheduling: When enabling per-vport QoS fails, the scheduling node is leaked
Impact
When enabling per-vport QoS fails, the scheduling node is leaked and the pointer left dangling. Per-VF QoS is the mechanism that stops one tenant's VF from starving the others' bandwidth, so failures here both leak host kernel memory and undermine the rate-limiting you sold as an isolation guarantee.
Who can reach it
Local, low-privileged - reached through the VF QoS configuration path on an SR-IOV host. An attacker who can make QoS enablement fail (resource exhaustion, invalid rates) reaches the bad path.
What to do
Upgrade the host kernel to 6.14 or the 6.13.6 stable backport. Rolling reboot of SR-IOV hosts. No firmware flash.
References
Related entries
- Linux x86/microcode/AMD - out-of-bounds on CPU-less NUMA nodes: The AMD microcode loader iterated every NUMA nodeCVE-2025-21991 · Linux x86/microcode/AMD - out-of-bounds on CPU-less NUMA nodesHigh
- Linux kernel RDMA core (hw_counters sysfs exposure across network namespaces): RDMA hardware counter sysfs attributesCVE-2025-22089 · Linux kernel RDMA core (hw_counters sysfs exposure across network namespaces)High
- Dell SmartFabric OS10 (command injection with elevated privileges): Local low-privilege attacker executes commandsCVE-2025-22472 · Dell SmartFabric OS10 (command injection with elevated privileges)High
- Dell SmartFabric OS10 (command injection, local): A low-privileged local attacker achieves code execution on the switchCVE-2025-22473 · Dell SmartFabric OS10 (command injection, local)High
- AMI AptioV BIOS (out-of-bounds write): Second local out-of-bounds write in the same AptioV advisoryCVE-2025-22831 · AMI AptioV BIOS (out-of-bounds write)High
- AMI AptioV BIOS (out-of-bounds write): Local out-of-bounds write in firmware causing data corruption and lossCVE-2025-22832 · AMI AptioV BIOS (out-of-bounds write)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.