Junglewise Threat Intelligence

CVE-2026-43464: Linux Kernel mlx5e reference counting error in XDP multi-buf

CVE-2026-43464 · Severity: high · CVSS 7.5 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Mellanox network driver could allow a remote attacker to cause a system crash. The issue occurs when the system processes specific types of network traffic using high-performance packet processing (XDP) on certain hardware. This can lead to memory management errors that result in a kernel panic, impacting the availability of the affected server or network appliance.

Technical details

A vulnerability exists in the mlx5e driver of the Linux kernel due to improper page fragment reference counting in the XDP multi-buffer (multi-buf) implementation for legacy Receive Queues (RQ). When XDP programs modify the layout of a buffer (e.g., via bpf_xdp_pull_data or bpf_xdp_adjust_tail), the driver fails to correctly track dropped fragments. This leads to a negative page pool reference count (pp_ref_count) during page release, triggering a kernel warning or 'splat' and subsequent system instability. The fix involves ensuring page fragment counting is performed on all original XDP buffer fragments across XDP_TX, XDP_REDIRECT, and XDP_PASS actions. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 6.6.115 to 6.7, 6.12.56 to 6.13, 6.17.6 to 6.18, 6.18.1 to 6.18.19, 6.19 to 6.19.9

Timeline

  • 2026-03-05: patched: Initial patch authored by Dragos Tatulea
  • 2026-05-08: disclosed: CVE-2026-43464 assigned and published

References

Related threats