Database/Firmware, BMC & network fabric
Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): Every time an XDP_TX transmit fails because the XDP send
Impact
Every time an XDP_TX transmit fails because the XDP send queue is full, the driver leaks both the frame and its DMA mapping. Under sustained load that is thousands of device-writable IOMMU mappings left standing for buffers the kernel no longer tracks, plus unbounded memory growth - the node runs out of memory and the stale mappings remain addressable by the NIC.
Who can reach it
A peer on the fabric drives it directly: flood the node hard enough that the XDP transmit queue backs up and every dropped XDP_TX frame leaks. Conditional on AF_XDP zero-copy being in use with an XDP program that returns XDP_TX on an mlx5 interface. No tenant device node required - the leak is in host memory shared by all tenants on the node.
What to do
Update to a kernel carrying the fix on your stream. Interim: stop using AF_XDP zero-copy with XDP_TX on mlx5 interfaces, or rate-limit untrusted ingress so the XDP send queue does not saturate.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): The transmit health reporter's dump callback casts itsCVE-2021-46931 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)Medium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): After a transmit-queue error triggers driver recovery, theCVE-2026-43466 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Two CPUs write to the internal control send queue withoutCVE-2026-64210 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/infiniband/hw/mlx5): When on-demand-paging translation-table population fails, the UMR pathCVE-2026-74396 · Linux kernel (drivers/infiniband/hw/mlx5)High
- Dell OMSA: unauthenticated path traversal exposes arbitrary files from the managed nodeCVE-2026-81481 · Dell OpenManage Server Administrator (path traversal, unauthenticated)High
- FreeIPMI ipmi-oem: stack buffer over-read when a BMC returns a short Fujitsu SEL responseCVE-2026-85505 · FreeIPMI ipmi-oem (Fujitsu get-sel-entry-long-text handler)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.