Executive brief
A vulnerability was identified in the Linux kernel's Mellanox Spectrum Ethernet driver. The issue occurs during the management of network access control lists (ACLs), where the system fails to check if certain internal lists are empty before attempting to process them. This can lead to a system crash or instability, potentially allowing a local user to cause a denial-of-service condition on affected networking hardware.
Technical details
A vulnerability exists in the mlxsw spectrum_acl_tcam driver within the Linux kernel due to incorrect usage of the list API. Specifically, the functions mlxsw_sp_acl_tcam_vchunk_migrate_all and mlxsw_sp_acl_tcam_vchunk_migrate_one call list_first_entry() without verifying that the vchunk_list or ventry_list are non-empty. This occurs during TCAM region rehashing/migration work. An attacker with local access could potentially trigger this condition to cause a kernel panic or denial of service. The fix involves adding list_empty() checks before attempting to access the first entry of these lists. Patches have been backported to multiple stable kernel branches including 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.8.y.
Affected products
- Linux Linux Kernel 5.1 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.158, 5.16 to 6.1.90, 6.2 to 6.6.30, 6.7 to 6.8.9, 6.9-rc1 to 6.9-rc5
Timeline
- 2024-04-22: patched: Initial patch authored by Ido Schimmel
- 2024-05-20: disclosed: CVE published
References
- https://git.kernel.org/stable/c/09846c2309b150b8ce4e0ce96f058197598fc530
- https://git.kernel.org/stable/c/0b2c13b670b168e324e1cf109e67056a20fd610a
- https://git.kernel.org/stable/c/4526a56e02da3725db979358964df9cd9c567154
- https://git.kernel.org/stable/c/64435b64e43d8ee60faa46c0cd04e323e8b2a7b0
- https://git.kernel.org/stable/c/ab4ecfb627338e440ae11def004c524a00d93e40
- https://git.kernel.org/stable/c/af8b593c3dd9df82cb199be65863af004b09fd97
- https://git.kernel.org/stable/c/b377add0f0117409c418ddd6504bd682ebe0bf79