Wind River Support Network

HomeDefectsLIN1024-10093
Fixed

LIN1024-10093 : Security Advisory - linux - CVE-2025-38109

Created: Jul 3, 2025    Updated: Jul 10, 2025
Resolved Date: Jul 10, 2025
Found In Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:EOL][EOL]net/mlx5: Fix ECVF vports unload on shutdown flow[EOL][EOL]Fix shutdown flow UAF when a virtual function is created on the embedded[EOL]chip (ECVF) of a BlueField device. In such case the vport acl ingress[EOL]table is not properly destroyed.[EOL][EOL]ECVF functionality is independent of ecpf_vport_exists capability and[EOL]thus functions mlx5_eswitch_(enable (disable)_pf_vf_vports() should not[EOL)test it when enabling/disabling ECVF vports.EOL][EOL]kernel log:[EOL][] refcount_t: underflow; use-after-free.[EOL][] WARNING: CPU: 3 PID: 1 at lib/refcount.c:28[EOL]   refcount_warn_saturate+0x124/0x220[EOL]----------------[EOL][] Call trace:[EOL][] refcount_warn_saturate+0x124/0x220[EOL][] tree_put_node+0x164/0x1e0 [mlx5_core][EOL][] mlx5_destroy_flow_table+0x98/0x2c0 [mlx5_core][EOL][] esw_acl_ingress_table_destroy+0x28/0x40 [mlx5_core][EOL][] esw_acl_ingress_lgcy_cleanup+0x80/0xf4 [mlx5_core][EOL][] esw_legacy_vport_acl_cleanup+0x44/0x60 [mlx5_core][EOL][] esw_vport_cleanup+0x64/0x90 [mlx5_core][EOL][] mlx5_esw_vport_disable+0xc0/0x1d0 [mlx5_core][EOL][] mlx5_eswitch_unload_ec_vf_vports+0xcc/0x150 [mlx5_core][EOL][] mlx5_eswitch_disable_sriov+0x198/0x2a0 [mlx5_core][EOL][] mlx5_device_disable_sriov+0xb8/0x1e0 [mlx5_core][EOL][] mlx5_sriov_detach+0x40/0x50 [mlx5_core][EOL][] mlx5_unload+0x40/0xc4 [mlx5_core][EOL][] mlx5_unload_one_devl_locked+0x6c/0xe4 [mlx5_core][EOL][] mlx5_unload_one+0x3c/0x60 [mlx5_core][EOL][] shutdown+0x7c/0xa4 [mlx5_core][EOL][] pci_device_shutdown+0x3c/0xa0[EOL][] device_shutdown+0x170/0x340[EOL][] __do_sys_reboot+0x1f4/0x2a0[EOL][] __arm64_sys_reboot+0x2c/0x40[EOL][] invoke_syscall+0x78/0x100[EOL][] el0_svc_common.constprop.0+0x54/0x184[EOL][] do_el0_svc+0x30/0xac[EOL][] el0_svc+0x48/0x160[EOL][] el0t_64_sync_handler+0xa4/0x12c[EOL][] el0t_64_sync+0x1a4/0x1a8[EOL][] --[ end trace 9c4601d68c70030e ]---

CREATE(Triage):(User=lchen-cn) [CVE-2025-38109 (https://nvd.nist.gov/vuln/detail/CVE-2025-38109)
Live chat
Online