Database/Firmware, BMC & network fabric
Linux mlxsw: PTP garbage collector calls napi_gro_receive outside NAPI context, corrupting the GRO list
Impact
On Mellanox Spectrum switches running Linux (mlxsw), the PTP garbage-collection workqueue finishes unmatched timestamp entries by calling napi_gro_receive() with a NAPI pointer stashed in the SKB control block at receive time. Because mlxsw enables threaded NAPI unconditionally, that poll may be running on another CPU, and the local_bh_disable() in the GC path guards only the local CPU - so both sides mutate the same GRO list and the kernel hits a list-corruption BUG. The reporter reproduces it simply by running ptp4l and waiting for a port to reach UNCALIBRATED/SLAVE, which makes this a realistic crash on any PTP-enabled Spectrum switch. For a GPU fabric that depends on these switches for time sync, the result is a switch control-plane panic that drops the box out of the topology until it reboots.
Who can reach it
Adjacent-network: PTP traffic on a Spectrum switch running mlxsw with PTP enabled, racing the switch's own RX NAPI thread. No authentication needed, but the trigger is normal PTP operation rather than a crafted attack - high complexity to aim deliberately.
What to do
Update the switch OS to a build carrying the mlxsw spectrum_ptp fix (three stable commits referenced); this is a switch software upgrade and reboot, taken one switch at a time so the fabric keeps a path. Where PTP is not actually needed on a given switch, disabling it removes the trigger until the upgrade lands.
References
Related entries
- RoCEv2 lossless Ethernet fabric - IEEE 802.1Qbb Priority Flow Control: RoCE requires a lossless network, which inNCVD-2018-001-rocev2-lossless-ethernet-fabric · RoCEv2 lossless Ethernet fabric - IEEE 802.1Qbb Priority Flow ControlHigh
- RoCEv2 lossless Ethernet fabric - IEEE 802.1Qbb Priority Flow Control: RoCE requires a lossless network, which inNCVD-2018-006-rocev2-lossless-ethernet-fabric · RoCEv2 lossless Ethernet fabric - IEEE 802.1Qbb Priority Flow ControlHigh
- InfiniBand/RoCE Communication Manager (CM) and RNIC connection-state resources: RNICs hold per-connection state in aNCVD-2021-005-infiniband-roce-communication-ma · InfiniBand/RoCE Communication Manager (CM) and RNIC connection-state resourcesHigh
- InfiniBand/RoCE Communication Manager (CM) and RNIC connection-state resources: RNICs hold per-connection state in aNCVD-2021-011-infiniband-roce-communication-ma · InfiniBand/RoCE Communication Manager (CM) and RNIC connection-state resourcesHigh
- OpenBMC bmcweb HTTP/1.1 Expect: 100-continue handling: bmcweb applies a 4 KB body limit to unauthenticated requestsNCVD-2026-001-openbmc-bmcweb-http-1-1-expect-1 · OpenBMC bmcweb HTTP/1.1 Expect: 100-continue handlingHigh
- OpenBMC bmcweb HTTP/2 Content-Length handling: bmcweb passes the client-supplied Content-Length straightNCVD-2026-002-openbmc-bmcweb-http-2-content-le · OpenBMC bmcweb HTTP/2 Content-Length handlingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.