Database/Kernel, userspace & hypervisor
Linux kernel mlx5_core RX datapath (striding RQ + XDP multi-buffer): The mlx5 driver assumed an XDP program could
Impact
The mlx5 driver assumed an XDP program could not change the xdp_buff layout. It can, via bpf_xdp_adjust_head/tail - and when it shrinks non-linear data the driver hits a BUG_ON, or builds a malformed skb. Any node running an XDP program on mlx5 (load balancers, DDoS scrubbers, CNI dataplanes like Cilium) can be crashed or memory-corrupted by remote packets. Jumbo-MTU routed fabrics are standard in datacenters, so the attacker does not need to be L2-adjacent.
Who can reach it
Unauthenticated remote sender, provided the target node runs an XDP program on an mlx5 interface with striding RQ.
What to do
Upgrade the host kernel to 6.18 or a stable backport (6.6.115, 6.12.56, 6.17.6). Rolling reboot. Interim: unload the XDP program from mlx5 interfaces if you can accept the performance/feature loss - a live config change.
References
Related entries
- Linux kernel iomap: length underflow on non-block-aligned reads returns a position past the folioCVE-2025-68794 · Linux kernel iomap (iomap_adjust_read_range block alignment)Critical
- Linux kernel (net/tls): Closing a kTLS socket cancelled the transmit work item, but the write-space callback couldCVE-2026-23240 · Linux kernel (net/tls)Critical
- Linux kernel (net/smc): An inbound SYN handled in softirq reads the smc_sock out of the listening TCP socket'sCVE-2026-23450 · Linux kernel (net/smc)Critical
- Linux kernel (net/tls): When the crypto engine backlogs a kTLS encrypt request, both the async completion callback andCVE-2026-31533 · Linux kernel (net/tls)Critical
- Linux kernel (net/ipv4): A child socket created from an inbound handshake is inserted into the TCP hash table beforeCVE-2026-43198 · Linux kernel (net/ipv4)Critical
- Linux kernel mlx5_core RX datapath (striding RQ, page_pool): A regression introduced by the fix for CVE-2025-40350CVE-2026-43465 · Linux kernel mlx5_core RX datapath (striding RQ, page_pool)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.