Executive brief
A vulnerability was identified in the Linux kernel's Mellanox Spectrum driver, which manages high-performance networking hardware. A flaw in how the system handles multicast network traffic statistics could allow a local attacker to cause a system crash or potentially execute unauthorized code. This occurs because the system may attempt to access memory that has already been deleted during network route updates.
Technical details
A use-after-free (UAF) vulnerability exists in `drivers/net/ethernet/mellanox/mlxsw/spectrum_mr.c` within the Linux kernel. The root cause is a missing mutex acquisition (`route_list_lock`) during a list entry deletion in the `mlxsw_sp_mr_route_add` function when replacing an existing route. While the driver periodically traverses the multicast route list to update kernel statistics, a concurrent route replacement can delete a node without proper synchronization, leading to a UAF in `mlxsw_sp_mr_stats_update`. This is a local attack vector requiring low privileges. The issue has been patched in multiple stable branches by ensuring the mutex is held during `list_del`.
Affected products
- Linux Linux Kernel f38656d06725 to 8ac1dacec458
Timeline
- 2025-12-02: patched: Initial patch authored by Ido Schimmel
- 2026-01-13: advisory: CVE-2025-68800 published
References
- https://git.kernel.org/stable/c/216afc198484fde110ebeafc017992266f4596ce
- https://git.kernel.org/stable/c/37ca08b35a27ce8fd8e74dd3fd2ae21c23b63b73
- https://git.kernel.org/stable/c/4049a6ace209f4ed150429f86ae796d7d6a4c22b
- https://git.kernel.org/stable/c/5f2831fc593c2b2efbff7dd0dd7441cec76adcd5
- https://git.kernel.org/stable/c/6e367c361a523a4b54fe618215c64a0ee189caf0
- https://git.kernel.org/stable/c/8ac1dacec458f55f871f7153242ed6ab60373b90
- https://git.kernel.org/stable/c/b957366f5611bbaba03dd10ef861283347ddcc88