Database/Kernel, userspace & hypervisor
Linux kernel mlx5_core IPsec RX offload: When hardware reports an xfrm state ID for a decrypted packet whose state
Impact
When hardware reports an xfrm state ID for a decrypted packet whose state has already been freed, the secpath extension is left attached with length zero and the policy check reads sp->xvec[-1], faulting the kernel. Any remote IPsec peer can crash a node doing hardware IPsec offload on ConnectX - relevant if you encrypt tenant traffic in flight across the fabric.
Who can reach it
Remote IPsec peer, unauthenticated with respect to this bug - the peer just needs to be in an SA that gets torn down while packets are in flight.
What to do
Upgrade the host kernel to 6.17 or a stable backport (6.6.102, 6.12.42, 6.15.10, 6.16.1). Rolling reboot of nodes doing IPsec offload. Interim: move IPsec off hardware offload to software xfrm (config change, CPU cost, no reboot).
References
Related entries
- Linux kernel (net/xfrm): Xfrm_alloc_spi could hand out an SPI that is already in use by another inbound SA, because theCVE-2025-39797 · Linux kernel (net/xfrm)High
- Linux kernel (net/smc): On hosts using soft-RoCE, the IB device has no DMA device, and the SMC buffer-mapping pathCVE-2025-39857 · Linux kernel (net/smc)High
- OpenSSL: QUIC listener queues unlimited pending connections, exhausting server memoryCVE-2026-14456 · OpenSSL QUIC server listener (pending-connection queue, 3.5+)High
- OpenSSL: raw-public-key endpoints with no certificate abort on a peer-sent signature_algorithms_cert extensionCVE-2026-14457 · OpenSSL TLS endpoint (RFC 7250 raw public keys, private key configured without a certificate)High
- OpenSSL QUIC: malformed INITIAL packet double-frees the record-layer object and kills the server processCVE-2026-18798 · OpenSSL QUIC server (port_default_packet_handler / port_bind_channel QRX object)High
- Linux kernel (drivers/nvme/target): Ordinary client I/O to an nvmet block-device namespace can hit a completion raceCVE-2026-23148 · Linux kernel (drivers/nvme/target)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.