Database/Kernel, userspace & hypervisor
Linux kernel mlx5_core MACsec offload: Deleting an offloaded MACsec RX secure channel frees the per-SC metadata_dst
Impact
Deleting an offloaded MACsec RX secure channel frees the per-SC metadata_dst with a call that ignores the reference count, while the RX datapath is concurrently taking a reference on it under RCU - a use-after-free reachable from the packet path. The kernel CNA notes it is reachable by cloud tenants with SR-IOV VFs, containers, or user/network namespaces without init-namespace root, so this is a container-to-host kernel corruption on nodes doing link-layer encryption.
Who can reach it
A tenant with an SR-IOV VF, a container with network-namespace capability, or a local user in a user namespace - combined with MACsec RX secure channel churn on an mlx5 interface.
What to do
Upgrade the host kernel to 7.2 or a stable backport (6.1.178, 6.6.145, 6.12.97, 6.18.40, 7.1.5). Rolling reboot. Interim: restrict unprivileged user namespaces and do not delegate MACsec configuration into tenant namespaces.
References
Related entries
- Linux kernel bpf: fork bailout frees an uninitialized task->bpf_storage, causing UAF or hangCVE-2026-72110 · Linux kernel BPF task local storage (copy_process / free_task bailout)High
- Linux kernel mm: DAX hotplug into an early section leaves ZONE_DEVICE tail struct pages uninitializedCVE-2026-72172 · Linux kernel mm/mm_init (ZONE_DEVICE compound_nr_pages on early sections)High
- Linux kernel (arch/x86/kvm/vmx): The nested vTPR versus TPR-threshold consistency check ran only after KVM had alreadyCVE-2026-72287 · Linux kernel (arch/x86/kvm/vmx)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A use-after-free in the amdkfd (KFD compute driverCVE-2026-72449 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel (net/xfrm): Xfrm_selector_match() compared selectors without checking that the selector family matches theCVE-2026-72450 · Linux kernel (net/xfrm)High
- Linux kernel BPF uprobe_multi: unchecked __get_user on user-supplied data allows local memory disclosure or corruptionCVE-2026-74258 · Linux kernel BPF (uprobe_multi link, missing access_ok on user data)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.