Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/hw/mlx5): An event subscription is published to the lookup table before its list head
Impact
An event subscription is published to the lookup table before its list head is initialized, so a device event that arrives in the same instant follows a poison pointer and faults in kernel context. One tenant's event subscription can panic a shared mlx5 node.
Who can reach it
A container holding /dev/infiniband/uverbs* that uses the mlx5 DEVX interface to subscribe to device events, with hardware events arriving concurrently - the tenant controls both the subscription rate and much of the event traffic. DEVX normally requires CAP_NET_RAW, so this needs a privileged container or a tenant explicitly granted raw-network capability; plain verbs users cannot reach it.
What to do
No fixed release is published in this record - apply the listed stable fix commits or run a current stable kernel. Interim: drop CAP_NET_RAW from tenant containers so the DEVX interface is unavailable, which closes this path entirely.
References
Related entries
- Linux kernel (drivers/infiniband/hw/mlx5): If the second of the two device-wide shared SRQs fails to allocate, theCVE-2026-46176 · Linux kernel (drivers/infiniband/hw/mlx5)High
- Linux kernel (drivers/infiniband/hw/mlx5): When on-demand-paging translation-table population fails, the UMR pathCVE-2026-74396 · Linux kernel (drivers/infiniband/hw/mlx5)High
- Linux kernel (drivers/infiniband/hw/mlx5): Memory-region deregistration hangs forever on the flagship AI-cluster NIC. ACVE-2025-21886 · Linux kernel (drivers/infiniband/hw/mlx5)Medium
- Linux kernel (drivers/infiniband/hw/mlx5): The memory-registration engine on the primary AI-cluster NIC wedgesCVE-2025-21892 · Linux kernel (drivers/infiniband/hw/mlx5)Medium
- Linux kernel (drivers/infiniband/hw/mlx5): Memory-region deregistration self-deadlocks under memory pressure. AnCVE-2025-38373 · Linux kernel (drivers/infiniband/hw/mlx5)Medium
- ASPEED LPC snoop driver channel teardown (drivers/soc/aspeed/aspeed-lpc-snoop.c): Unbinding the LPC snoop driver tearsCVE-2025-38487 · ASPEED LPC snoop driver channel teardown (drivers/soc/aspeed/aspeed-lpc-snoop.c)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.