CVE-2026-72341
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix publication race for priv->channel_stats[]
mlx5e_channel_stats_alloc() publishes a new entry to priv->channel_stats[] and then increments priv->stats_nch as a publication token, but neither store carries any memory barrier:
Concurrent readers compute the loop bound from priv->stats_nch and then dereference priv->channel_stats[i] using plain accesses, e.g.
On weakly-ordered architectures (ARM, PowerPC, RISC-V) the writes to channel_stats[ix] and stats_nch may become visible to other CPUs out of program order. A reader can observe stats_nch == N while still seeing channel_stats[N-1] == NULL, leading to a NULL pointer dereference in the channel_stats loop.
Leer descripción completaMostrar menos
This has been observed in production on BlueField-3 DPUs (arm64), where ovs-vswitchd queries netdev statistics over netlink during NIC bringup, racing mlx5e_open_channel() -> mlx5e_channel_stats_alloc() on another CPU:
Add mlx5e_stats_nch_write() and mlx5e_stats_nch_read() helpers in en.h that wrap the smp_store_release()/smp_load_acquire() pair on stats_nch. The release/acquire pair establishes the contract:
Publish the stats_nch increment via mlx5e_stats_nch_write() in the writer (mlx5e_channel_stats_alloc()), and read stats_nch via mlx5e_stats_nch_read() in all readers: mlx5e RX/TX queue stats, mlx5e_get_base_stats(), ethtool channels stats, IPoIB stats, the sw_stats fold and the HV VHCA stats agent.
Detalles técnicos trazas, registros y código del informe original
priv->channel_stats[ix] = kvzalloc_node(...);
if (!priv->channel_stats[ix])
return -ENOMEM;
priv->stats_nch++;
for (i = 0; i < priv->stats_nch; i++) {
struct mlx5e_channel_stats *cs = priv->channel_stats[i];
... cs->rq.packets ...
}
Unable to handle kernel NULL pointer dereference at virtual address 0x840
Hardware name: BlueField-3 DPU
pc : mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]
Call trace:
mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]
dev_get_stats+0x50/0xc0
ovs_vport_get_stats+0x38/0xac [openvswitch]
ovs_vport_cmd_fill_info+0x194/0x290 [openvswitch]
ovs_vport_cmd_get+0xbc/0x10c [openvswitch]
genl_family_rcv_msg_doit+0xd0/0x160
genl_rcv_msg+0xec/0x1f0
netlink_rcv_skb+0x64/0x130
genl_rcv+0x40/0x60
netlink_unicast+0x2fc/0x370
netlink_sendmsg+0x1dc/0x454
...
__arm64_sys_sendmsg+0x2c/0x40
stats_nch == N => channel_stats[0..N-1] are visible and non-NULL.CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72341",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "fa691d0c9c0812b9045f3a9420862e47b3b92518",
"lessThan": "5c7e3755abf663f033de24f917b77685e9543045",
"versionType": "git"
},
{
"status": "affected",
"version": "fa691d0c9c0812b9045f3a9420862e47b3b92518",
"lessThan": "815515ec68f527ca755cb1e2c1ff9148f6b3ea56",
"versionType": "git"
},
{
"status": "affected",
"version": "fa691d0c9c0812b9045f3a9420862e47b3b92518",
"lessThan": "5a799714e8ca0bce9ea40694f49914cf1adbbaa9",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en.h",
"drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c",
"drivers/net/ethernet/mellanox/mlx5/core/en_main.c",
"drivers/net/ethernet/mellanox/mlx5/core/en_stats.c",
"drivers/net/ethernet/mellanox/mlx5/core/ipoib/ipoib.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en.h",
"drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c",
"drivers/net/ethernet/mellanox/mlx5/core/en_main.c",
"drivers/net/ethernet/mellanox/mlx5/core/en_stats.c",
"drivers/net/ethernet/mellanox/mlx5/core/ipoib/ipoib.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:22:07.403",
"references": [
{
"url": "https://git.kernel.org/stable/c/5a799714e8ca0bce9ea40694f49914cf1adbbaa9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5c7e3755abf663f033de24f917b77685e9543045",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/815515ec68f527ca755cb1e2c1ff9148f6b3ea56",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix publication race for priv->channel_stats[]\n\nmlx5e_channel_stats_alloc() publishes a new entry to\npriv->channel_stats[] and then increments priv->stats_nch as a\npublication token, but neither store carries any memory barrier:\n\n\tpriv->channel_stats[ix] = kvzalloc_node(...);\n\tif (!priv->channel_stats[ix])\n\t\treturn -ENOMEM;\n\tpriv->stats_nch++;\n\nConcurrent readers compute the loop bound from priv->stats_nch and\nthen dereference priv->channel_stats[i] using plain accesses, e.g.\n\n\tfor (i = 0; i < priv->stats_nch; i++) {\n\t\tstruct mlx5e_channel_stats *cs = priv->channel_stats[i];\n\t\t... cs->rq.packets ...\n\t}\n\nOn weakly-ordered architectures (ARM, PowerPC, RISC-V) the writes to\nchannel_stats[ix] and stats_nch may become visible to other CPUs out\nof program order. A reader can observe stats_nch == N while still\nseeing channel_stats[N-1] == NULL, leading to a NULL pointer\ndereference in the channel_stats loop.\n\nThis has been observed in production on BlueField-3 DPUs (arm64),\nwhere ovs-vswitchd queries netdev statistics over netlink during NIC\nbringup, racing mlx5e_open_channel() -> mlx5e_channel_stats_alloc()\non another CPU:\n\n Unable to handle kernel NULL pointer dereference at virtual address 0x840\n Hardware name: BlueField-3 DPU\n pc : mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]\n Call trace:\n mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]\n dev_get_stats+0x50/0xc0\n ovs_vport_get_stats+0x38/0xac [openvswitch]\n ovs_vport_cmd_fill_info+0x194/0x290 [openvswitch]\n ovs_vport_cmd_get+0xbc/0x10c [openvswitch]\n genl_family_rcv_msg_doit+0xd0/0x160\n genl_rcv_msg+0xec/0x1f0\n netlink_rcv_skb+0x64/0x130\n genl_rcv+0x40/0x60\n netlink_unicast+0x2fc/0x370\n netlink_sendmsg+0x1dc/0x454\n ...\n __arm64_sys_sendmsg+0x2c/0x40\n\nAdd mlx5e_stats_nch_write() and mlx5e_stats_nch_read() helpers in en.h\nthat wrap the smp_store_release()/smp_load_acquire() pair on stats_nch.\nThe release/acquire pair establishes the contract:\n\n stats_nch == N => channel_stats[0..N-1] are visible and non-NULL.\n\nPublish the stats_nch increment via mlx5e_stats_nch_write() in the\nwriter (mlx5e_channel_stats_alloc()), and read stats_nch via\nmlx5e_stats_nch_read() in all readers: mlx5e RX/TX queue stats,\nmlx5e_get_base_stats(), ethtool channels stats, IPoIB stats, the\nsw_stats fold and the HV VHCA stats agent."
}
],
"lastModified": "2026-08-17T06:18:37.903",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}