« Volver al listado

CVE-2026-74717

Estado: RecibidaAlta (7.5)—

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5: fw_tracer, return NULL on create error

Tracer creation can fail by returning either NULL or ERR_PTR. The return value is stored without a check on the device, and users treat ERR_PTR and NULL the same way. This also causes a crash in the core dump logic, which is missing the ERR_PTR check and ends up dereferencing it, as shown in the trace below.

Switch tracer creation to return NULL on failure only, so callers only need a single NULL check.

Detalles técnicos trazas, registros y código del informe original
  Internal error: Oops: 0000000096000006 [#1]  SMP
  Modules linked in: mlx5_ib ib_uverbs ib_core ipv6 mlx5_core
  CPU: 1 UID: 0 PID: 12 Comm: kworker/u16:0 Not tainted 6.19.7 #1 PREEMPT(none)
  Workqueue: mlx5_health0001:01:00.0 mlx5_fw_reporter_err_work [mlx5_core]
  pstate: a3400009 (NzCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
  pc : mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core]
  lr : mlx5_fw_tracer_trigger_core_dump_general+0x40/0xe0 [mlx5_core]
  sp : ffff800081cf3c40
  x29: ffff800081cf3c90 x28: 0000000000000000 x27: 0000000000000000
  x26: ffff000080018828 x25: 0000000000000000 x24: ffff000080304a05
  x23: ffff800081cf3d80 x22: ffff0000847e01a0 x21: 0000000000000000
  x20: ffff0000847e01a0 x19: ffffffffffffffa1 x18: ffff80008310bbf0
  x17: ffff800080119650 x16: ffff80008010df54 x15: ffff80008010d4ac
  x14: ffff800079c202e4 x13: ffff80008002fe60 x12: ffff800080119650
  x11: ffff80008010df54 x10: ffff80008010d4ac x9 : ffff800079c203d8
  x8 : ffff800081cf3c88 x7 : 0000000000000000 x6 : 0000000000000000
  x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000030
  x2 : 0000000000000008 x1 : 0000000000000000 x0 : 00000000c5c4000e
  Call trace:
   mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core] (P)
   mlx5_fw_reporter_dump+0x30/0x2e0 [mlx5_core]
   devlink_health_do_dump+0x9c/0x160
   devlink_health_report+0x1c0/0x288
   mlx5_fw_reporter_err_work+0xac/0xc0 [mlx5_core]
   process_one_work+0x15c/0x3d8
   worker_thread+0x18c/0x320
   kthread+0x148/0x228
   ret_from_fork+0x10/0x20
  Code: b9400000 5ac00800 7a401800 540003ca (3940a260)
  ---[ end trace 0000000000000000 ]---
  Kernel panic - not syncing: Oops: Fatal exception
  SMP: stopping secondary CPUs
  Kernel Offset: disabled
  CPU features: 0x000000,00078031,75fce5a1,35fffe67
  Memory Limit: none
  ---[ end Kernel panic - not syncing: Oops: Fatal exception ]---

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74717",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
              "lessThan": "47fe0d2571e5b446a0f0b0c1d6b99f55e51f5cc0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
              "lessThan": "ee41ea49c4ab0e4015919f52ad23ec251d3b39d3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
              "lessThan": "04599570c3a18f9ae7aad36825eb46f3dcd2c4e3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
              "lessThan": "9a416f000285a94c1b723877547981dec8132434",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
              "lessThan": "b1d6375b9a63c9dc7e5e780d3ea9b126fe30d6cb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
              "lessThan": "80094352bd40ba54a33731f9c22872493983ed6d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
              "lessThan": "4aafa600d93e9551c1f24e785d57cbd4adf021d5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
              "lessThan": "af39eb111ce6b5eba9c08513b62c4868eb7e7fd5",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.152",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.104",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.45",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.9",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-22T16:16:46.570",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/04599570c3a18f9ae7aad36825eb46f3dcd2c4e3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/47fe0d2571e5b446a0f0b0c1d6b99f55e51f5cc0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4aafa600d93e9551c1f24e785d57cbd4adf021d5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/80094352bd40ba54a33731f9c22872493983ed6d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9a416f000285a94c1b723877547981dec8132434",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/af39eb111ce6b5eba9c08513b62c4868eb7e7fd5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b1d6375b9a63c9dc7e5e780d3ea9b126fe30d6cb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ee41ea49c4ab0e4015919f52ad23ec251d3b39d3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: fw_tracer, return NULL on create error\n\nTracer creation can fail by returning either NULL or ERR_PTR.\nThe return value is stored without a check on the device, and users\ntreat ERR_PTR and NULL the same way.\nThis also causes a crash in the core dump logic, which is missing the\nERR_PTR check and ends up dereferencing it, as shown in the trace below.\n\nSwitch tracer creation to return NULL on failure only, so callers only\nneed a single NULL check.\n\n  Internal error: Oops: 0000000096000006 [#1]  SMP\n  Modules linked in: mlx5_ib ib_uverbs ib_core ipv6 mlx5_core\n  CPU: 1 UID: 0 PID: 12 Comm: kworker/u16:0 Not tainted 6.19.7 #1 PREEMPT(none)\n  Workqueue: mlx5_health0001:01:00.0 mlx5_fw_reporter_err_work [mlx5_core]\n  pstate: a3400009 (NzCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n  pc : mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core]\n  lr : mlx5_fw_tracer_trigger_core_dump_general+0x40/0xe0 [mlx5_core]\n  sp : ffff800081cf3c40\n  x29: ffff800081cf3c90 x28: 0000000000000000 x27: 0000000000000000\n  x26: ffff000080018828 x25: 0000000000000000 x24: ffff000080304a05\n  x23: ffff800081cf3d80 x22: ffff0000847e01a0 x21: 0000000000000000\n  x20: ffff0000847e01a0 x19: ffffffffffffffa1 x18: ffff80008310bbf0\n  x17: ffff800080119650 x16: ffff80008010df54 x15: ffff80008010d4ac\n  x14: ffff800079c202e4 x13: ffff80008002fe60 x12: ffff800080119650\n  x11: ffff80008010df54 x10: ffff80008010d4ac x9 : ffff800079c203d8\n  x8 : ffff800081cf3c88 x7 : 0000000000000000 x6 : 0000000000000000\n  x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000030\n  x2 : 0000000000000008 x1 : 0000000000000000 x0 : 00000000c5c4000e\n  Call trace:\n   mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core] (P)\n   mlx5_fw_reporter_dump+0x30/0x2e0 [mlx5_core]\n   devlink_health_do_dump+0x9c/0x160\n   devlink_health_report+0x1c0/0x288\n   mlx5_fw_reporter_err_work+0xac/0xc0 [mlx5_core]\n   process_one_work+0x15c/0x3d8\n   worker_thread+0x18c/0x320\n   kthread+0x148/0x228\n   ret_from_fork+0x10/0x20\n  Code: b9400000 5ac00800 7a401800 540003ca (3940a260)\n  ---[ end trace 0000000000000000 ]---\n  Kernel panic - not syncing: Oops: Fatal exception\n  SMP: stopping secondary CPUs\n  Kernel Offset: disabled\n  CPU features: 0x000000,00078031,75fce5a1,35fffe67\n  Memory Limit: none\n  ---[ end Kernel panic - not syncing: Oops: Fatal exception ]---"
    }
  ],
  "lastModified": "2026-08-25T06:18:57.310",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}