Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/hw/mlx5): Memory-region deregistration self-deadlocks under memory pressure. An
Impact
Memory-region deregistration self-deadlocks under memory pressure. An allocation made while holding the page-mapping lock can drive reclaim, which calls back into the same driver's invalidation handler and blocks on the lock it already holds - the tenant's task hangs unkillably and the mlx5 registration path is blocked for everything else on the node.
Who can reach it
A tenant container holding /dev/infiniband/uverbs* on mlx5 hardware deregistering an on-demand-paging memory region while the node is under memory pressure. Both halves are tenant-influenceable: the tenant chooses when to deregister and can raise memory pressure itself, which is exactly the condition a busy shared GPU node is already in.
What to do
Update to 6.12.37 / 6.14 or later. Interim: disable on-demand paging for tenant workloads so ODP regions are never created, and keep node memory headroom high enough that reclaim is not entered during RDMA teardown.
References
Related entries
- Linux kernel (drivers/infiniband/hw/mlx5): An event subscription is published to the lookup table before its list headCVE-2025-38387 · Linux kernel (drivers/infiniband/hw/mlx5)Medium
- Linux kernel (drivers/infiniband/hw/mlx5): If the second of the two device-wide shared SRQs fails to allocate, theCVE-2026-46176 · Linux kernel (drivers/infiniband/hw/mlx5)High
- Linux kernel (drivers/infiniband/hw/mlx5): When on-demand-paging translation-table population fails, the UMR pathCVE-2026-74396 · Linux kernel (drivers/infiniband/hw/mlx5)High
- Linux kernel (drivers/infiniband/hw/mlx5): Memory-region deregistration hangs forever on the flagship AI-cluster NIC. ACVE-2025-21886 · Linux kernel (drivers/infiniband/hw/mlx5)Medium
- Linux kernel (drivers/infiniband/hw/mlx5): The memory-registration engine on the primary AI-cluster NIC wedgesCVE-2025-21892 · Linux kernel (drivers/infiniband/hw/mlx5)Medium
- ASPEED LPC snoop driver channel teardown (drivers/soc/aspeed/aspeed-lpc-snoop.c): Unbinding the LPC snoop driver tearsCVE-2025-38487 · ASPEED LPC snoop driver channel teardown (drivers/soc/aspeed/aspeed-lpc-snoop.c)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.