Database/Firmware, BMC & network fabric
Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): After a transmit-queue error triggers driver recovery, the
Impact
After a transmit-queue error triggers driver recovery, the software DMA FIFO's producer and consumer indices are left out of sync, so the driver unmaps DMA addresses recorded before the recovery. The node tears down IOMMU mappings that no longer correspond to the buffers being freed - stale-mapping teardown on a shared NIC, which means either a live mapping is revoked underneath in-flight DMA or a dead IOVA is left mapped, on top of repeated queue failures.
Who can reach it
Reachable over the network: the recovery path is entered on a transmit error completion, which a peer on the Ethernet/RDMA fabric can provoke through congestion, malformed or oversized traffic, and link-level abuse against the node's uplink. No tenant device node is required - the corrupted state is in the host's shared TX path, so any tenant sharing that NIC is exposed.
What to do
Update to a kernel carrying the fix on your stream. There is no useful runtime workaround: the code runs whenever an error CQE occurs on a TX queue. Reduce exposure by rate-limiting or isolating untrusted senders on the fabric until nodes are rebooted onto a fixed kernel.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): Every time an XDP_TX transmit fails because the XDP sendCVE-2026-53229 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): The transmit health reporter's dump callback casts itsCVE-2021-46931 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)Medium
- Insyde InsydeH2O (unverified firmware volume in the boot chain): Certain firmware volumes are executed without beingCVE-2026-6484 · Insyde InsydeH2O (unverified firmware volume in the boot chain)High
- InsydeH2O UEFI firmware: embedded UEFI Shell can be used to bypass Secure BootCVE-2026-6485 · InsydeH2O UEFI firmware (embedded UEFI Shell)High
- Supermicro IPMI BMC firmware: Every affected BMC shares one TLS private key and one SSH host key, baked into theCVE-2013-3619 · Supermicro IPMI BMC firmwareHigh
- Dell iDRAC6/iDRAC7 IPMI 1.5 session handling: IPMI 1.5 session IDs are handed out incrementally from a small pool, soCVE-2014-8272 · Dell iDRAC6/iDRAC7 IPMI 1.5 session handlingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.