Database/Firmware, BMC & network fabric
Linux kernel mlxsw (Spectrum switch router, neighbour table): The driver stored neighbour pointers without holding
Impact
The driver stored neighbour pointers without holding a reference, taking one only when the neighbour was used by a nexthop - a slab use-after-free when updating neighbour entries. Reproduced on an NVIDIA SN5600. Neighbour churn on a busy leaf is normal operation, so this is a switch crash that arrives on its own schedule and takes a rack's uplinks with it.
Who can reach it
Local on the switch, driven by neighbour table churn - which an attacker on an attached network can amplify by cycling ARP/ND entries.
What to do
Upgrade the switch OS to a build carrying kernel 6.19 or a stable backport (5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.64, 6.18.3). Switch OS upgrade and reload - fabric rolling window, one switch at a time with ECMP draining.
References
Related entries
- Linux bnxt_re RoCE driver (bnxt_re_copy_err_stats out-of-bounds write): Out-of-bounds write in the Broadcom RoCECVE-2025-71092 · Linux bnxt_re RoCE driver (bnxt_re_copy_err_stats out-of-bounds write)High
- Linux kernel InfiniBand user MAD interface (ib_umad, /dev/infiniband/umad*): A process with access to the user MADCVE-2026-23243 · Linux kernel InfiniBand user MAD interface (ib_umad, /dev/infiniband/umad*)High
- Dell iDRAC Service Module (iSM) for Windows and Linux: Improper access control in the host-side iDRAC Service ModuleCVE-2026-23856 · Dell iDRAC Service Module (iSM) for Windows and LinuxHigh
- Linux kernel InfiniBand core dmabuf umem (GPUDirect RDMA path): When mapping a dmabuf-backed RDMA memory region failsCVE-2026-43128 · Linux kernel InfiniBand core dmabuf umem (GPUDirect RDMA path)High
- Linux bnxt_en driver (RSS context delete logic): RSS contexts are not always freed in firmware when the driver deletesCVE-2026-43260 · Linux bnxt_en driver (RSS context delete logic)High
- Linux kernel Soft-RoCE shared receive queue (rdma_rxe, rxe_srq_from_init): If the copy_to_user() that returns the SRQCVE-2026-45852 · Linux kernel Soft-RoCE shared receive queue (rdma_rxe, rxe_srq_from_init)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.