Database/Firmware, BMC & network fabric
Linux kernel i2c-mlxbf (BlueField DPU I2C controller): mlxbf_i2c_init_resource() frees a resource struct and then reads
Impact
mlxbf_i2c_init_resource() frees a resource struct and then reads a field out of it to build the error code - a use-after-free on the DPU during I2C controller initialisation. Same subsystem as the earlier BlueField I2C stack overflow, which is the real signal: the DPU's platform glue has repeatedly shipped memory-safety bugs, and that is the layer your infrastructure services sit on.
Who can reach it
Local on the DPU, reached on the I2C init error path during driver probe.
What to do
Upgrade the DPU Arm-side kernel to 7.2 or one of the wide stable backports (5.10.261 through 7.1.5), delivered as a DOCA/BFOS package upgrade or BFB re-image plus DPU reset. Low urgency alone - bundle into the next BFB refresh alongside the other BlueField platform fixes.
References
Related entries
- Linux kernel mlxsw: failed LAG index allocation leaks a LAG reference on Spectrum switchesCVE-2026-72308 · Linux kernel mlxsw (Spectrum switch driver, LAG join error path)Unscored
- Linux kernel bnxt_re: uninitialised shared page mapped to userspace leaks kernel memoryCVE-2026-74584 · Linux kernel bnxt_re RDMA driver (ucontext shared page)Unscored
- Linux kernel PMBus hwmon: type confusion in the alert path reads past the attribute allocationCVE-2026-74711 · Linux kernel hwmon pmbus core (pmbus_notify attribute type confusion)Unscored
- Linux kernel hns_roce: bonding teardown order leaks resources and leaves a stale netdev notifierCVE-2026-80625 · Linux kernel hns_roce (RoCE bonding resource teardown order)Unscored
- Linux kernel Soft-RoCE: modify_qp frees the rd_atomic array using the new size, writing out of boundsCVE-2026-80863 · Linux kernel RDMA/rxe (free_rd_atomic_resources during modify_qp)Unscored
- Linux kernel rdma_rxe: use-after-free in the responder task when modify_qp swaps the RD-atomic resource arrayCVE-2026-80864 · Linux kernel Soft-RoCE responder (rdma_rxe, IB_QP_MAX_DEST_RD_ATOMIC modify_qp)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.