Junglewise Threat Intelligence

CVE-2026-53229: Linux Kernel mlx5e DMA and xdp_frame leak in XDP_TX

CVE-2026-53229 · Severity: info · Published 2026-06-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Mellanox network driver can cause a memory leak when high-speed data processing (XDP) fails. This occurs when the system is under heavy network load and cannot process outgoing packets fast enough, leading to a gradual exhaustion of system resources. Over time, this can degrade system performance or lead to a crash, impacting the availability of servers using affected Mellanox network hardware.

Technical details

A resource leak exists in the mlx5e_xmit_xdp_buff() function within the Linux kernel's Mellanox network driver. When sq->xmit_xdp_frame() returns false (typically when the transmit queue is full), the driver fails to unmap the DMA address and free the xdp_frame allocated by xdp_convert_zc_to_xdp_frame(). Because the xdpi_fifo push only occurs on success, the completion path cannot recover these entries, leading to a DMA and memory leak. This is reachable via network traffic triggering XDP_TX actions. Patches have been released for various stable kernel branches to ensure proper cleanup via dma_unmap_single and xdp_return_frame on failure.

Affected products

  • Linux Linux 5.3 to 6.12.94, 6.18.36, 7.0.13

Timeline

  • 2026-06-04: other: Patch authored
  • 2026-06-25: disclosed: CVE published

References