-

CVE-2026-64472

vfio/mlx5: Fix racy bitfields and tighten struct layout

In the Linux kernel, the following vulnerability has been resolved:

vfio/mlx5: Fix racy bitfields and tighten struct layout

Bitfield operations are not atomic, they use a read-modify-write
pattern, therefore we should be careful not to pack bitfields that
can be concurrently updated into the same storage unit.

This split takes a binary approach: flags that are only modified
pre/post open/close remain bitfields, flags modified from user
action, including actions that reach across to another device (ex.
reset) use dedicated storage units.

Note mlx5_vhca_page_tracker.status is relocated to fill the alignment
hole this split exposes.

Bitfield justifications:

  migrate_cap: written only in mlx5vf_cmd_set_migratable() at probe
  chunk_mode: written only in mlx5vf_cmd_set_migratable() at probe
  mig_state_cap: written only in mlx5vf_cmd_set_migratable() at probe

Dedicated storage units:

  mdev_detach: written in the VF attach/detach event notifier
               mlx5fv_vf_event() at runtime
  log_active: written in mlx5vf_start_page_tracker()/
              mlx5vf_stop_page_tracker() during runtime dirty tracking
  deferred_reset: written in mlx5vf_state_mutex_unlock()/
                  mlx5vf_pci_aer_reset_done() during runtime reset handling
  is_err: set by tracker error handling and dirty-log polling at runtime
  object_changed: set by tracker event handling and cleared by dirty-log
                  polling at runtime
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 61a2f1460fd03285ea34c1a235f2f50f71e13a1f
Version < 1dd99b8f4e143592e12e5a77e7b538bc698116cb
Status affected
Version 61a2f1460fd03285ea34c1a235f2f50f71e13a1f
Version < f1db80a67da928a92ba460ede1be52d8941f46be
Status affected
Version 61a2f1460fd03285ea34c1a235f2f50f71e13a1f
Version < 399d806f998f7a25405fc1b97227e579aead24af
Status affected
Version 61a2f1460fd03285ea34c1a235f2f50f71e13a1f
Version < 7ed120b1a007bace57c461805519d70e1af44e59
Status affected
Version 61a2f1460fd03285ea34c1a235f2f50f71e13a1f
Version < 39d163627b51886492bf31f66cb02c94613d2287
Status affected
Version 61a2f1460fd03285ea34c1a235f2f50f71e13a1f
Version < f2365a63b02ddea32e7db78b742c2503ec7b81f1
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.19
Status affected
Version 0
Version < 5.19
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1dd99b8f4e143592e12e5a77e7b538bc698116cb
https://git.kernel.org/stable/c/f1db80a67da928a92ba460ede1be52d8941f46be
https://git.kernel.org/stable/c/399d806f998f7a25405fc1b97227e579aead24af
https://git.kernel.org/stable/c/7ed120b1a007bace57c461805519d70e1af44e59
https://git.kernel.org/stable/c/39d163627b51886492bf31f66cb02c94613d2287
https://git.kernel.org/stable/c/f2365a63b02ddea32e7db78b742c2503ec7b81f1