Database/Firmware, BMC & network fabric
Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Two CPUs write to the internal control send queue without
Impact
Two CPUs write to the internal control send queue without holding a lock, so one overwrites the other's work-queue entries and advances the producer index over them. The queue that feeds receive-buffer posting ends up with garbage descriptors ('Bad OP in ICOSQ CQE'), which stalls receive on that channel and takes packet reception away from every workload sharing the interface.
Who can reach it
Racy path is in NAPI poll, so sustained receive load plus an interrupt-affinity change is enough to hit it - a busy fabric peer supplies the load. Conditional on AF_XDP zero-copy being active on the mlx5 interface, which puts the XSK UMR posting path and the IRQ-trigger path on the same queue. No tenant device node needed; it is host-shared driver state.
What to do
Update to a kernel carrying the fix on your stream. Interim: stop running AF_XDP zero-copy sockets on mlx5 interfaces, and pin IRQ affinity so channels do not migrate between CPUs under load.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Nothing orders the PTP send-queue tracking list againstCVE-2024-26858 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)Medium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When the driver runs out of firmware command slots, the workCVE-2025-21662 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)Medium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): The async firmware-command context can be freed while aCVE-2022-50726 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): A userspace DEVX consumer can issue a firmware command opcodeCVE-2023-53340 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When a regular receive queue is reactivated after an AF_XDPCVE-2023-53394 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Adding a TC flower rule while the device is in NIC mode makesCVE-2023-54216 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.