Database/Firmware, BMC & network fabric
Linux kernel (drivers/vfio/pci/mlx5): Migration and dirty-tracking state flags for an mlx5 VF were packed into shared
Impact
Migration and dirty-tracking state flags for an mlx5 VF were packed into shared bitfields updated non-atomically from concurrent paths, including a reset on one device reaching across to another. A lost update means the driver's view of deferred_reset, dirty-logging active, or error state diverges from reality - a passthrough NIC can be treated as reset when it was not, or dirty-page logging can be believed active when it is off, which silently corrupts a migrated tenant's memory.
Who can reach it
Driven by tenant-visible actions on an mlx5 SR-IOV VF bound to mlx5-vfio-pci: a tenant issuing device resets or migration state changes through /dev/vfio/* while the operator's dirty-tracking or VF event handling runs concurrently. Conditional on Mellanox/NVIDIA ConnectX VFs with the mlx5 vfio variant driver - which is the standard configuration for SR-IOV NIC passthrough in GPU clouds.
What to do
Update to a stable kernel carrying commits 1dd99b8f / f1db80a6. Interim: bind VFs to plain vfio-pci where live migration and dirty tracking are not needed, and serialize tenant-initiated resets against migration operations in the VMM.
References
Related entries
- Linux kernel (drivers/vfio/pci/mlx5): Pages allocated for a device migration buffer are not freed when adding them toCVE-2024-56742 · Linux kernel (drivers/vfio/pci/mlx5)Medium
- TPM 2.0: timing side channel in RSA OAEP decryption can expose TPM-managed key material and forge attestationsCVE-2026-6727 · TPM 2.0 reference implementation (RSA OAEP decryption timing)Medium
- Arista EOS: RADIUS proxy suppresses CoA and Disconnect-Requests for local 802.1X sessionsCVE-2026-73449 · Arista EOS (RADIUS proxy with dynamic authorization / 802.1X CoA)Medium
- Arista EOS (security ACL vs NAT rule interaction): A security ACL drop rule is bypassed when a NAT ACL permit ruleCVE-2021-28511 · Arista EOS (security ACL vs NAT rule interaction)Medium
- AMI MegaRAC SPx 12 (BMC default TLS certificate): The BMC ships with a hard-coded default TLS certificate, so HTTPSCVE-2021-4228 · AMI MegaRAC SPx 12 (BMC default TLS certificate)Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC web session management): Session fixation combined with sessions that never properlyCVE-2021-46279 · AMI MegaRAC SPx 12 / SPx 13 (BMC web session management)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.