Executive brief
A vulnerability in the Linux kernel's Mellanox Spectrum driver could allow a local user to cause a system instability or crash. The issue occurs during the 'rehash' process, which manages how network filters are organized in hardware memory. If an error occurs during this process, the system may incorrectly track its progress, leading to internal consistency errors and potential service disruption.
Technical details
A vulnerability exists in the mlxsw: spectrum_acl_tcam component of the Linux kernel. The rehash delayed work migrates filters between regions by iterating over chunks and entries. When the work runs out of credits or encounters an error, it saves markers to resume later. However, the driver was resetting the chunk marker to NULL without resetting the relative entry markers. This caused the migration to resume from an invalid state, potentially treating a chunk structure as an entry structure. This logic error triggers kernel warnings (e.g., in mlxsw_afk_encode) and can lead to system instability. The fix involves ensuring all markers (chunk and entry) are reset simultaneously via a new helper function.
Affected products
- Linux Linux kernel 5.1 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.158, 5.16 to 6.1.90, 6.2 to 6.6.30, 6.7 to 6.8.9, 6.9-rc1 to 6.9-rc5
Timeline
- 2024-04-22: patched: Initial patch authored
- 2024-05-20: advisory: CVE-2024-36007 published
References
- https://git.kernel.org/stable/c/039992b6d2df097c65f480dcf269de3d2656f573
- https://git.kernel.org/stable/c/0b88631855026b55cad901ac28d081e0f358e596
- https://git.kernel.org/stable/c/17e9e0bbae652b9b2049e51699e93dfa60b2988d
- https://git.kernel.org/stable/c/1d76bd2a0034d0d08045c1c6adf2235d88982952
- https://git.kernel.org/stable/c/743edc8547a92b6192aa1f1b6bb78233fa21dc9b
- https://git.kernel.org/stable/c/751d352858108314efd33dddd5a9a2b6bf7d6916
- https://git.kernel.org/stable/c/e890456051fe8c57944b911defb3e6de91315861