Executive brief
A vulnerability in the Linux kernel's Mellanox network driver could cause a system crash. This occurs when the system attempts to recover from a network transmission timeout, accidentally accessing memory that has already been cleared. This issue primarily affects system stability and availability for servers using specific Mellanox network hardware.
Technical details
A use-after-free (UAF) vulnerability exists in the mlx5e_tx_reporter_timeout_recover function within the Linux kernel's Mellanox mlx5 driver. The root cause is the function accessing the 'sq->netdev' pointer after the underlying channel and its Send Queues (SQs) have been torn down and freed by mlx5e_safe_reopen_channels(). An attacker or a system event triggering a TX timeout could cause a kernel panic (KASAN splat). The fix involves referencing 'priv->netdev' instead, which remains valid throughout the teardown process. Patches have been released for various stable kernel branches including 6.18.x, 6.19.x, and 7.0.x.
Affected products
- Linux Linux Kernel 6.18.14 to 6.18.34, 6.19.4 to 6.20, 7.0 to 7.0.11
Timeline
- 2026-05-13: other: Patch authored
- 2026-07-19: disclosed: CVE published