GPU VulnDB

Database/Firmware, BMC & network fabric

Linux mlxsw: PTP garbage collector calls napi_gro_receive outside NAPI context, corrupting the GRO list

CVSS 7.5CVE-2026-98050Firmware, BMC & network fabriccurated

Impact

On Mellanox Spectrum switches running Linux (mlxsw), the PTP garbage-collection workqueue finishes unmatched timestamp entries by calling napi_gro_receive() with a NAPI pointer stashed in the SKB control block at receive time. Because mlxsw enables threaded NAPI unconditionally, that poll may be running on another CPU, and the local_bh_disable() in the GC path guards only the local CPU - so both sides mutate the same GRO list and the kernel hits a list-corruption BUG. The reporter reproduces it simply by running ptp4l and waiting for a port to reach UNCALIBRATED/SLAVE, which makes this a realistic crash on any PTP-enabled Spectrum switch. For a GPU fabric that depends on these switches for time sync, the result is a switch control-plane panic that drops the box out of the topology until it reboots.

Who can reach it

Adjacent-network: PTP traffic on a Spectrum switch running mlxsw with PTP enabled, racing the switch's own RX NAPI thread. No authentication needed, but the trigger is normal PTP operation rather than a crafted attack - high complexity to aim deliberately.

What to do

Update the switch OS to a build carrying the mlxsw spectrum_ptp fix (three stable commits referenced); this is a switch software upgrade and reboot, taken one switch at a time so the fabric keeps a path. Where PTP is not actually needed on a given switch, disabling it removes the trigger until the upgrade lands.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.