Database/Kernel, userspace & hypervisor
Linux kernel mlx5_core TX timeout devlink health reporter: The TX timeout recovery handler accesses the netdev pointer
Impact
The TX timeout recovery handler accesses the netdev pointer after the channel and its send queues have already been torn down and freed - a use-after-free in the code path that is supposed to recover the NIC from a stall. So the failure mode is: the NIC wedges under load, the recovery machinery fires, and instead of recovering it corrupts host kernel memory.
Who can reach it
Remote and unauthenticated in effect - an attacker who can drive enough traffic to induce a TX timeout on the mlx5 interface reaches the recovery path. No credentials on the host.
What to do
Upgrade the host kernel to a build carrying the fix (mainline 7.x and current stable series). Rolling reboot of the fleet. There is no useful config mitigation - you cannot safely turn off TX timeout recovery.
References
Related entries
- Linux kernel mlx5_core TX timeout devlink health reporter: The TX timeout recovery path runs without the state lock, soCVE-2024-45019 · Linux kernel mlx5_core TX timeout devlink health reporterHigh
- Linux kernel BPF devmap: cloning fragmented XDP frames for broadcast redirect reads out of boundsCVE-2026-64355 · Linux kernel BPF devmap (XDP broadcast redirect clone path)Critical
- Linux kernel krb5 crypto: use-after-free when an async AEAD backend is bound to the enctypeCVE-2026-64439 · Linux kernel krb5 crypto helpers (rfc3961_simplified / rfc8009_aes2 AEAD paths)Critical
- Linux kernel (drivers/nvme/target): A client connected to your NVMe-oF TCP target can drive a reference-count underflowCVE-2026-64534 · Linux kernel (drivers/nvme/target)Critical
- Linux kernel NVMe-oF TCP target (nvmet-tcp, data-digest mismatch handling): With data digests enabled, a digestCVE-2026-64535 · Linux kernel NVMe-oF TCP target (nvmet-tcp, data-digest mismatch handling)Critical
- Linux kernel SMC-R connection data control (smc_cdc_rx_handler socket lifetime): The CDC receive handler looks theCVE-2026-64541 · Linux kernel SMC-R connection data control (smc_cdc_rx_handler socket lifetime)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.