-

CVE-2026-80739

net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock

In case __mlx5e_add_fdb_flow() fails in lower levels, the flow is
deleted via mlx5e_tc_del_flow(), and mlx5e_tc_del_flow() is acquiring
ESW devcom lock without condition. In addition, in case of peer_flow,
__mlx5e_add_fdb_flow() is called while holding ESW devcom comp lock.
This results in an AA deadlock.

To fix this, introduce a new PEER flag that is set on flows created as
peer flows (the duplicate flows on peer devices), and check it in
mlx5e_tc_del_flow() before acquiring ESW devcom lock.

Lockdep splat:
============================================
WARNING: possible recursive locking detected
============================================
 Possible unsafe locking scenario:
       CPU0
       ----
  lock(&comp->lock_key#2);
  lock(&comp->lock_key#2);
 *** DEADLOCK ***
Call Trace:
 <TASK>
 dump_stack_lvl+0x69/0xa0
 print_deadlock_bug.cold+0xbd/0xca
 __lock_acquire+0x1671/0x2ec0
 lock_acquire+0x10e/0x2e0
 down_read+0x95/0x430
 mlx5_devcom_for_each_peer_begin+0x4e/0xe0 [mlx5_core]
 mlx5e_tc_del_flow+0x11d/0xa70 [mlx5_core]
 mlx5e_flow_put+0x99/0x100 [mlx5_core]
 __mlx5e_add_fdb_flow+0x409/0xf00 [mlx5_core]
 mlx5e_configure_flower+0x2a86/0x4100 [mlx5_core]
 mlx5e_rep_setup_tc_cls_flower+0x12f/0x1b0 [mlx5_core]
 mlx5e_rep_setup_tc_cb+0x153/0x750 [mlx5_core]
 tc_setup_cb_add+0x1dc/0x470
 fl_change+0x2f4d/0x626d [cls_flower]
 tc_new_tfilter+0x79b/0x2310
 rtnetlink_rcv_msg+0x778/0xad0
 do_syscall_64+0x70/0x960
 entry_SYSCALL_64_after_hwframe+0x4b/0x53
 </TASK>
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 04de7dda7394fa9c2b0fc9cec65661d9b4f0d04d
Version < 607adbda01053abf5f93e322fe39325da8828cb8
Status affected
Version 04de7dda7394fa9c2b0fc9cec65661d9b4f0d04d
Version < 585df8643081e6f616579bc52cd49ac823a57c82
Status affected
Version 04de7dda7394fa9c2b0fc9cec65661d9b4f0d04d
Version < ff9e7d5e3500be389ce7a0e46db3a77149830bc9
Status affected
Version 04de7dda7394fa9c2b0fc9cec65661d9b4f0d04d
Version < 7165fe321c61ec138850c02f030f274797761f5f
Status affected
Version 04de7dda7394fa9c2b0fc9cec65661d9b4f0d04d
Version < 6ddfba2ea98db21b001e0e5c472499156224650c
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.0
Status affected
Version 0
Version < 5.0
Status unaffected
Version <= 6.6.*
Version 6.6.152
Status unaffected
Version <= 6.12.*
Version 6.12.104
Status unaffected
Version <= 6.18.*
Version 6.18.45
Status unaffected
Version <= 7.1.*
Version 7.1.9
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.098
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/607adbda01053abf5f93e322fe39325da8828cb8
https://git.kernel.org/stable/c/585df8643081e6f616579bc52cd49ac823a57c82
https://git.kernel.org/stable/c/ff9e7d5e3500be389ce7a0e46db3a77149830bc9
https://git.kernel.org/stable/c/7165fe321c61ec138850c02f030f274797761f5f
https://git.kernel.org/stable/c/6ddfba2ea98db21b001e0e5c472499156224650c