Executive brief
A vulnerability in the Linux kernel's Mellanox network driver can cause a system crash. The issue occurs when the system incorrectly manages internal networking rules, leading to a memory error when those rules are deleted. This could potentially be used to disrupt network services or cause a denial-of-service (DoS) condition on affected servers.
Technical details
A NULL pointer dereference vulnerability exists in the net/mlx5 driver of the Linux kernel due to improper linking of flow steering (fs) rules into the internal tree structure. The function add_rule_fg previously only added rules to the tree if they had a reference count of 1. However, create_flow_handle could create a new rule and reference it multiple times during a single handle creation, resulting in a reference count greater than 1 for a rule not yet linked to the tree. When such a rule is later deleted, the del_sw_hw_rule function attempts to access a NULL parent pointer, causing a kernel panic. This issue has been resolved by ensuring new rules are linked into the tree based on the absence of a parent pointer rather than the reference count.
Affected products
- Linux Linux Kernel 4.10 to 4.19.313, 4.20 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.156, 5.16 to 6.1.87, 6.2 to 6.6.28, 6.7 to 6.8.7
Timeline
- 2024-05-20: advisory: Initial publication of the CVE record
- 2024-05-02: patched: Fix committed to the Linux stable kernel tree
References
- https://git.kernel.org/stable/c/1263b0b26077b1183c3c45a0a2479573a351d423
- https://git.kernel.org/stable/c/2e8dc5cffc844dacfa79f056dea88002312f253f
- https://git.kernel.org/stable/c/3d90ca9145f6b97b38d0c2b6b30f6ca6af9c1801
- https://git.kernel.org/stable/c/5cf5337ef701830f173b4eec00a4f984adeb57a0
- https://git.kernel.org/stable/c/7aaee12b804c5e0374e7b132b6ec2158ff33dd64
- https://git.kernel.org/stable/c/7c6782ad4911cbee874e85630226ed389ff2e453
- https://git.kernel.org/stable/c/adf67a03af39095f05d82050f15813d6f700159d