Executive brief
A vulnerability in the Linux kernel's Mellanox network driver could allow a remote attacker to cause a system crash. The issue occurs when the system handles specific IPsec security events, leading to an invalid internal state that halts the operating system. This affects servers using Mellanox hardware for encrypted network traffic.
Technical details
A 'scheduling while atomic' vulnerability exists in the mlx5e_ipsec_init_macs() function within the Linux kernel's Mellanox mlx5 driver. The root cause is a call to mlx5_query_mac_address(), which invokes mlx5_cmd_exec()—a function that may sleep—from within the mlx5e_ipsec_handle_event workqueue, which operates in an atomic context. An attacker could potentially trigger this condition via network-based IPsec events, leading to a kernel panic or system hang. The fix involves replacing the hardware query with a direct copy of the MAC address from the netdev structure, avoiding the sleeping call. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux Kernel 6.2 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6, 7.0-rc1
Timeline
- 2026-02-24: other: Patch authored by Jianbo Liu
- 2026-05-06: disclosed: CVE published by kernel.org
- 2026-05-11: advisory: NVD initial analysis completed