Database/Kernel, userspace & hypervisor
Linux kernel mlx5_core flow steering / flow counters (hardware steering): Use-after-free releasing
Impact
Use-after-free releasing the hardware-steering action of a local flow counter - the refcount and mutex were never initialized and the counter struct can already be freed when the rule is deleted. Notably it is reached through an ib_uverbs ioctl into mlx5_ib_destroy_flow, so a tenant holding an RDMA verbs handle can drive host kernel memory corruption in the NIC's flow-steering tables.
Who can reach it
Local, low-privileged - reachable from a userspace RDMA verbs handle destroying a flow, not only from privileged tc/devlink paths.
What to do
Upgrade the host kernel to 6.17 or the 6.16.10 stable backport. Rolling reboot of the fleet.
References
Related entries
- Linux kernel (net/smc): SMC-D loopback registers DMBs (the direct memory buffers a peer reads and writes) out ofCVE-2025-40012 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Connect() on an SMC socket takes the destination device pointer out of the dst cache without aCVE-2025-40064 · Linux kernel (net/smc)High
- Linux kernel (drivers/gpu/drm/scheduler): When adding reservation-object dependencies to a job, the helper alreadyCVE-2025-40096 · Linux kernel (drivers/gpu/drm/scheduler)High
- Linux kernel (drivers/gpu/drm/vmwgfx): A guest process can get a node left in the vmwgfx validation hash table afterCVE-2025-40111 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel BPF: tailcalls ignore expected_attach_type, yielding NULL deref and bypassed context checksCVE-2025-40123 · Linux kernel BPF tailcall map compatibility (__bpf_prog_map_compatible)High
- Linux kernel SMC: dst entry can be freed under smc_clc_prfx_set during connect(), a local UAFCVE-2025-40139 · Linux kernel SMC protocol (smc_clc_prfx_set destination cache use-after-free)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.