Database/Firmware, BMC & network fabric
Linux kernel mlx5_core IPsec offload / eswitch mode interlock: The acquire-SA path unconditionally calls
Impact
The acquire-SA path unconditionally calls mlx5_eswitch_unblock_mode() without a matching block, underflowing the counter that is supposed to prevent eswitch mode transitions while IPsec offload is live. Once that interlock is broken, switchdev/legacy mode can be flipped out from under active offloads - and eswitch mode is what defines VF steering and isolation on the NIC. A remote packet is enough to start unwinding the enforcement point for tenant separation.
Who can reach it
Network-reachable, unauthenticated: a remote TCP SYN routed through an administrator-configured outbound IPsec policy reaches the vulnerable acquire-SA callback. No account on the host.
What to do
Upgrade the host kernel to 7.1 or a stable backport (6.18.34, 7.0.11). Rolling reboot of every node running mlx5 IPsec full offload. Interim: if you are not depending on hardware IPsec offload, disable it on the mlx5 interfaces (config change, no reboot) to take the path out of reach.
References
Related entries
- MikroTik RouterOS: pre-auth btest session leaks kernel buffer data and can restart the deviceCVE-2026-67277 · MikroTik RouterOS (btest bandwidth test service)High
- Dell OpenManage Enterprise: authenticated SQL injection exposes management database contentsCVE-2026-71176 · Dell OpenManage Enterprise (SQL injection)High
- Linux KVM - intra-host migration/mirroring of SEV-SNP VMs: KVM allowed intra-host migration and mirroring of SEV-SNPCVE-2026-72286 · Linux KVM - intra-host migration/mirroring of SEV-SNP VMsHigh
- Linux kernel (drivers/infiniband/hw/bnxt_re): The variable-WQE send-queue slot count came straight from userspace withCVE-2026-72497 · Linux kernel (drivers/infiniband/hw/bnxt_re)High
- Linux bnxt_re RoCE driver (CQ toggle page use-after-free): The completion-queue variant of the toggle-pageCVE-2026-72499 · Linux bnxt_re RoCE driver (CQ toggle page use-after-free)High
- Linux bnxt_re RoCE driver (SRQ toggle page use-after-free): A use-after-free in the Broadcom RoCE driver — the toggleCVE-2026-72500 · Linux bnxt_re RoCE driver (SRQ toggle page use-after-free)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.