Executive brief
A race condition was identified in the Linux kernel's Mellanox mlx5 network driver when using AF_XDP (XSK) zero-copy networking. Under specific conditions where network processing is moved between processor cores, the driver could perform unprotected memory writes, potentially leading to system instability or kernel crashes. This affects high-performance networking environments using Mellanox hardware.
Technical details
A race condition exists in the mlx5e driver's XSK implementation due to unlocked writing to the Internal Control Operations Send Queue (ICOSQ). The vulnerability occurs during NAPI polling when a CPU affinity change coincides with pending XSK work; mlx5e_trigger_irq() may be called concurrently with mlx5e_xsk_alloc_rx_mpwqe() or mlx5e_trigger_napi_icosq() on different CPUs. Because the ICOSQ uses an optimized locking scheme that does not account for this cross-CPU trigger, concurrent access leads to corrupted queue states and 'Bad OP' completion queue errors. The fix involves switching to the asynchronous ICOSQ which utilizes a robust locking mechanism.
Affected products
- Linux Linux db05815b36cbd486c86fd002dfa81c9af6245e25 to 8d3b91e7d81000d295cd914d4d9d6f860252e2bf
Timeline
- 2026-05-13: patched: Initial patch authored by Dragos Tatulea
- 2026-07-24: advisory: NVD publication date