NVIDIA/Mellanox ConnectX driver (mlx5_ib DEVX subscribe-event unwind): DEVX is the raw device-command escape hatch that
Impact
DEVX is the raw device-command escape hatch that lets a userspace RDMA library drive the adapter directly. The subscribe-event handler linked its event object into the shared subscription list before initialising the fields the error path uses, so a failing eventfd_ctx_fdget() - trivially forced by passing a bad file descriptor - dereferences an unset ev_file and calls the xarray deallocator with an unset key. A tenant chooses when to fail, which makes the unwind path reachable on demand on the interface that speaks directly to adapter firmware.
Who can reach it
Local, unprivileged. A tenant calls the DEVX subscribe-event ioctl with an invalid eventfd.
What to do
Kernel update ordering the initialisation before list insertion and making the xarray deallocation exactly-once. If DEVX is not needed by tenant workloads, restricting it is the sharpest control - but note that some accelerated userspace libraries require it, so check before disabling.
References
Related entries
- Linux amdgpu VCN: integer overflow in dec_msg buffer count lets the parser run past the message BOCVE-2026-89818 · Linux kernel drm/amdgpu VCN decode message parser (num_buffers bounds check)High
- Linux kernel amdkfd: unbounded copy_to_user in get_wave_state leaks adjacent kernel memoryCVE-2026-97496 · Linux kernel drm/amdkfd (get_wave_state, CRIU restore path)High
- NVIDIA vGPU Manager (vGPU plugin): Stack buffer overflow in the vGPU Manager with enough control for a guest to place aCVE-2021-1099 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): A guest-supplied string may not be null-terminated, and the host plugin reads pastCVE-2021-1120 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): The vGPU plugin double-frees hostCVE-2022-31614 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2022-50079 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.