Database/Kernel, userspace & hypervisor
Linux kernel mlx5_core RX datapath (striding RQ, page_pool): A regression introduced by the fix for CVE-2025-40350
Impact
A regression introduced by the fix for CVE-2025-40350: dropped XDP fragments stopped being counted driver-side, so page_pool reference counts go negative and mlx5 releases 64 fragments against a refcount of 63. Remote packets corrupt page-pool refcounting in the host kernel. Worth flagging to operators as a pattern - patching the earlier RX bug without moving to a current stable re-exposes you.
Who can reach it
Unauthenticated remote sender to a node running XDP multi-buffer on mlx5 striding RQ, on a kernel that carries the CVE-2025-40350 fix but not this one.
What to do
Upgrade the host kernel to 7.0 or a stable backport (6.18.19, 6.19.9). Rolling reboot. Do not stop at the CVE-2025-40350 fix level - verify your running kernel carries both.
References
Related entries
- Linux kernel nvmet-tcp - ICReq/teardown race and data-digest error paths: Three lifecycle bugs an initiator can driveCVE-2026-46135 · Linux kernel nvmet-tcp - ICReq/teardown race and data-digest error pathsCritical
- Linux kernel (net/rds): If RDS/IB queue-pair setup fails after the send ring is allocated but before the receive ringCVE-2026-53355 · Linux kernel (net/rds)Critical
- Linux kernel (net/xfrm): IPTFS fragment consumption loses the shared-page marker, so ESP concludes the payload pagesCVE-2026-53363 · Linux kernel (net/xfrm)Critical
- Linux kernel - LIO iSCSI target CHAP authentication, drivers/target/iscsi/iscsi_target_auth.cCVE-2026-63886 · Linux kernel - LIO iSCSI target CHAP authentication, drivers/target/iscsi/iscsi_target_auth.cCritical
- Linux kernel (net/tls): A particular kTLS ring state builds a scatterlist whose chain link points directly at anotherCVE-2026-64046 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When the kTLS transmit scatterlist ring wraps, the chain link that stitches the tail back toCVE-2026-64047 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.