Executive brief
A vulnerability was identified in the Linux kernel's Mellanox mlx4 driver, which handles high-performance networking. The issue involves improper synchronization during network event processing, which could lead to a system crash if an event occurs before the hardware interface is fully initialized. This could impact the availability of servers using these specific network adapters.
Technical details
A vulnerability in the Linux kernel RDMA/mlx4 driver stems from the misuse of Read-Copy-Update (RCU) in the mlx4_srq_event() function. While the radix_tree lookup is RCU-safe, the mlx4_srq structure itself is not freed using RCU, and the code fails to protect against partially initialized objects. An attacker or a specifically timed network event could trigger a null pointer dereference or use-after-free condition if an event is delivered before the Shared Receive Queue (SRQ) object is fully initialized. The fix replaces the RCU read lock with a spinlock and utilizes refcount_inc_not_zero() to ensure the object is valid and fully initialized before use.
Affected products
- Linux Linux Kernel mlx4 driver
Timeline
- 2026-04-28: other: Patch authored
- 2026-05-28: advisory: NVD publication date