Executive brief
The Linux kernel's mlx5 network driver contains a flaw in its traffic control peer flow cleanup logic when handling Link Aggregation Group (LAG) configurations. When the driver attempts to clean up peer flows during LAG unpairing, it can access invalid memory if the peer device is not available, causing the kernel to crash and potentially disrupting network connectivity on affected systems.
Technical details
The vulnerability exists in the net/mlx5e traffic control (TC) module where the mlx5e_tc_del_fdb_peers_flow() function is called without first validating whether mlx5_lag_get_dev_seq() successfully retrieved the peer device sequence number. When a peer device is not in the LAG or no device is marked as master, the function returns an error; however, the cleanup code does not check for this failure before dereferencing memory, leading to a kernel crash. The flaw is triggered during LAG unpair operations, which are local administrative actions on systems running the mlx5 driver. The fix involves skipping peer flow cleanup when the LAG sequence lookup fails. Patches are available in the upstream Linux kernel.
Affected products
- Linux Linux kernel <UNKNOWN>
Timeline
- 2026-08-15: disclosed