In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Add a timeout to acquire the command queue semaphore Prevent forced completion handling on an entry that has not yet be…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Add a timeout to acquire the command queue semaphore Prevent forced completion handling on an entry that has not yet been assigned an index, causing an out of bounds access on idx = -22. Instead of waiting indefinitely for the sem, blocking flow now waits for index to be allocated or a sem acquisition timeout before beginning the timer for FW completion. Kernel log example: mlx5_core 0000:06:00.0: wait_func_handle_…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/2d0962d05c93de391ce85f6e764df895f47c8918 Patch
- https://git.kernel.org/stable/c/485d65e1357123a697c591a5aeb773994b247ad7 Patch
- https://git.kernel.org/stable/c/4baae687a20ef2b82fde12de3c04461e6f2521d6 Patch
- https://git.kernel.org/stable/c/94024332a129c6e4275569d85c0c1bfb2ae2d71b Patch
- https://git.kernel.org/stable/c/f9caccdd42e999b74303c9b0643300073ed5d319 Patch
- https://git.kernel.org/stable/c/2d0962d05c93de391ce85f6e764df895f47c8918 Patch
- https://git.kernel.org/stable/c/485d65e1357123a697c591a5aeb773994b247ad7 Patch
- https://git.kernel.org/stable/c/4baae687a20ef2b82fde12de3c04461e6f2521d6 Patch
- https://git.kernel.org/stable/c/94024332a129c6e4275569d85c0c1bfb2ae2d71b Patch
- https://git.kernel.org/stable/c/f9caccdd42e999b74303c9b0643300073ed5d319 Patch
Timeline
- nvd_ingest NVD