CVE-2024-26586 (GCVE-0-2024-26586)
Vulnerability from cvelistv5
Published
2024-02-22 16:13
Modified
2026-08-05 11:26
Summary
In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix stack corruption When tc filters are first added to a net device, the corresponding local port gets bound to an ACL group in the device. The group contains a list of ACLs. In turn, each ACL points to a different TCAM region where the filters are stored. During forwarding, the ACLs are sequentially evaluated until a match is found. One reason to place filters in different regions is when they are added with decreasing priorities and in an alternating order so that two consecutive filters can never fit in the same region because of their key usage. In Spectrum-2 and newer ASICs the firmware started to report that the maximum number of ACLs in a group is more than 16, but the layout of the register that configures ACL groups (PAGT) was not updated to account for that. It is therefore possible to hit stack corruption [1] in the rare case where more than 16 ACLs in a group are required. Fix by limiting the maximum ACL group size to the minimum between what the firmware reports and the maximum ACLs that fit in the PAGT register. Add a test case to make sure the machine does not crash when this condition is hit. [1] Kernel panic - not syncing: stack-protector: Kernel stack is corrupted in: mlxsw_sp_acl_tcam_group_update+0x116/0x120 [...] dump_stack_lvl+0x36/0x50 panic+0x305/0x330 __stack_chk_fail+0x15/0x20 mlxsw_sp_acl_tcam_group_update+0x116/0x120 mlxsw_sp_acl_tcam_group_region_attach+0x69/0x110 mlxsw_sp_acl_tcam_vchunk_get+0x492/0xa20 mlxsw_sp_acl_tcam_ventry_add+0x25/0xe0 mlxsw_sp_acl_rule_add+0x47/0x240 mlxsw_sp_flower_replace+0x1a9/0x1d0 tc_setup_cb_add+0xdc/0x1c0 fl_hw_replace_filter+0x146/0x1f0 fl_change+0xc17/0x1360 tc_new_tfilter+0x472/0xb90 rtnetlink_rcv_msg+0x313/0x3b0 netlink_rcv_skb+0x58/0x100 netlink_unicast+0x244/0x390 netlink_sendmsg+0x1e4/0x440 ____sys_sendmsg+0x164/0x260 ___sys_sendmsg+0x9a/0xe0 __sys_sendmsg+0x7a/0xc0 do_syscall_64+0x40/0xe0 entry_SYSCALL_64_after_hwframe+0x63/0x6b
Impacted products
Vendor Product Version
Linux Linux Version: c3ab435466d5109b2c7525a3b90107d4d9e918fc
Version: c3ab435466d5109b2c7525a3b90107d4d9e918fc
Version: c3ab435466d5109b2c7525a3b90107d4d9e918fc
Version: c3ab435466d5109b2c7525a3b90107d4d9e918fc
Version: c3ab435466d5109b2c7525a3b90107d4d9e918fc
Version: c3ab435466d5109b2c7525a3b90107d4d9e918fc
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-26586",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-02-22T20:41:19.395721Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-07-05T17:21:02.147Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T00:07:19.636Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/56750ea5d15426b5f307554e7699e8b5f76c3182"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/348112522a35527c5bcba933b9fefb40a4f44f15"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/6fd24675188d354b1cad47462969afa2ab09d819"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/2f5e1565740490706332c06f36211d4ce0f88e62"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/a361c2c1da5dbb13ca67601cf961ab3ad68af383"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/483ae90d8f976f8339cf81066312e1329f2d3706"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/mellanox/mlxsw/spectrum_acl_tcam.c",
            "tools/testing/selftests/drivers/net/mlxsw/spectrum-2/tc_flower.sh"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "56750ea5d15426b5f307554e7699e8b5f76c3182",
              "status": "affected",
              "version": "c3ab435466d5109b2c7525a3b90107d4d9e918fc",
              "versionType": "git"
            },
            {
              "lessThan": "348112522a35527c5bcba933b9fefb40a4f44f15",
              "status": "affected",
              "version": "c3ab435466d5109b2c7525a3b90107d4d9e918fc",
              "versionType": "git"
            },
            {
              "lessThan": "6fd24675188d354b1cad47462969afa2ab09d819",
              "status": "affected",
              "version": "c3ab435466d5109b2c7525a3b90107d4d9e918fc",
              "versionType": "git"
            },
            {
              "lessThan": "2f5e1565740490706332c06f36211d4ce0f88e62",
              "status": "affected",
              "version": "c3ab435466d5109b2c7525a3b90107d4d9e918fc",
              "versionType": "git"
            },
            {
              "lessThan": "a361c2c1da5dbb13ca67601cf961ab3ad68af383",
              "status": "affected",
              "version": "c3ab435466d5109b2c7525a3b90107d4d9e918fc",
              "versionType": "git"
            },
            {
              "lessThan": "483ae90d8f976f8339cf81066312e1329f2d3706",
              "status": "affected",
              "version": "c3ab435466d5109b2c7525a3b90107d4d9e918fc",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/mellanox/mlxsw/spectrum_acl_tcam.c",
            "tools/testing/selftests/drivers/net/mlxsw/spectrum-2/tc_flower.sh"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.19"
            },
            {
              "lessThan": "4.19",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.209",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.148",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.79",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.14",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.8",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.209",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.148",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.79",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.14",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.2",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: spectrum_acl_tcam: Fix stack corruption\n\nWhen tc filters are first added to a net device, the corresponding local\nport gets bound to an ACL group in the device. The group contains a list\nof ACLs. In turn, each ACL points to a different TCAM region where the\nfilters are stored. During forwarding, the ACLs are sequentially\nevaluated until a match is found.\n\nOne reason to place filters in different regions is when they are added\nwith decreasing priorities and in an alternating order so that two\nconsecutive filters can never fit in the same region because of their\nkey usage.\n\nIn Spectrum-2 and newer ASICs the firmware started to report that the\nmaximum number of ACLs in a group is more than 16, but the layout of the\nregister that configures ACL groups (PAGT) was not updated to account\nfor that. It is therefore possible to hit stack corruption [1] in the\nrare case where more than 16 ACLs in a group are required.\n\nFix by limiting the maximum ACL group size to the minimum between what\nthe firmware reports and the maximum ACLs that fit in the PAGT register.\n\nAdd a test case to make sure the machine does not crash when this\ncondition is hit.\n\n[1]\nKernel panic - not syncing: stack-protector: Kernel stack is corrupted in: mlxsw_sp_acl_tcam_group_update+0x116/0x120\n[...]\n dump_stack_lvl+0x36/0x50\n panic+0x305/0x330\n __stack_chk_fail+0x15/0x20\n mlxsw_sp_acl_tcam_group_update+0x116/0x120\n mlxsw_sp_acl_tcam_group_region_attach+0x69/0x110\n mlxsw_sp_acl_tcam_vchunk_get+0x492/0xa20\n mlxsw_sp_acl_tcam_ventry_add+0x25/0xe0\n mlxsw_sp_acl_rule_add+0x47/0x240\n mlxsw_sp_flower_replace+0x1a9/0x1d0\n tc_setup_cb_add+0xdc/0x1c0\n fl_hw_replace_filter+0x146/0x1f0\n fl_change+0xc17/0x1360\n tc_new_tfilter+0x472/0xb90\n rtnetlink_rcv_msg+0x313/0x3b0\n netlink_rcv_skb+0x58/0x100\n netlink_unicast+0x244/0x390\n netlink_sendmsg+0x1e4/0x440\n ____sys_sendmsg+0x164/0x260\n ___sys_sendmsg+0x9a/0xe0\n __sys_sendmsg+0x7a/0xc0\n do_syscall_64+0x40/0xe0\n entry_SYSCALL_64_after_hwframe+0x63/0x6b"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is reached through the rtnetlink/`tc filter add` path via the `sendmsg()` syscall on a netlink socket, requiring local system access. Network packets traversing the switch cannot reach the ACL group configuration code, which only runs on control-plane filter installation.\nAC:L - The attacker deterministically forces more than 16 ACLs into one group by adding flower filters with decreasing priorities in an alternating key layout so consecutive filters cannot share a TCAM region \u2014 the exact sequence the added selftest performs. There is no race, no timing window, and no dependence on unpredictable memory layout.\nPR:L - `rtnetlink_rcv_msg` gates filter creation on CAP_NET_ADMIN, a delegated capability well short of full root that is routinely granted to network-management daemons and `--net=host --cap-add=NET_ADMIN` containers on the switch platforms where mlxsw is deployed. Such a semi-privileged context crosses a real boundary by smashing the kernel stack.\nUI:N - The attacker installs the tc filters entirely on their own; no victim action, no mount, and no file open is involved. The overflow occurs synchronously inside the attacker\u0027s own syscall.\nS:U - The corrupted memory is the kernel stack of the calling thread, and the impact stays within the kernel\u0027s own security authority. No hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - Each out-of-bounds iteration read-modify-writes stack memory beyond the 112-byte `pagt_pl` buffer, and the resulting corruption of saved registers and the return address is the kind of memory corruption that can be steered toward disclosing kernel memory. Per the higher-severity rule for out-of-bounds writes on the kernel stack, this is scored High.\nI:H - This is an out-of-bounds write that walks linearly past the end of a fixed 112-byte stack buffer, overwriting the stack canary, saved registers, and return address with values partially controlled by the attacker (region IDs and the `multi` bit). Out-of-bounds writes into a kernel stack frame are treated as High integrity impact.\nA:H - The documented and reproducible outcome is `Kernel panic - not syncing: stack-protector: Kernel stack is corrupted`, an unconditional panic that takes down the entire switch. The condition is triggered on demand and repeatably."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:26:05.421Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/56750ea5d15426b5f307554e7699e8b5f76c3182"
        },
        {
          "url": "https://git.kernel.org/stable/c/348112522a35527c5bcba933b9fefb40a4f44f15"
        },
        {
          "url": "https://git.kernel.org/stable/c/6fd24675188d354b1cad47462969afa2ab09d819"
        },
        {
          "url": "https://git.kernel.org/stable/c/2f5e1565740490706332c06f36211d4ce0f88e62"
        },
        {
          "url": "https://git.kernel.org/stable/c/a361c2c1da5dbb13ca67601cf961ab3ad68af383"
        },
        {
          "url": "https://git.kernel.org/stable/c/483ae90d8f976f8339cf81066312e1329f2d3706"
        }
      ],
      "title": "mlxsw: spectrum_acl_tcam: Fix stack corruption",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-26586",
    "datePublished": "2024-02-22T16:13:31.796Z",
    "dateReserved": "2024-02-19T14:20:24.125Z",
    "dateUpdated": "2026-08-05T11:26:05.421Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/56750ea5d15426b5f307554e7699e8b5f76c3182\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/348112522a35527c5bcba933b9fefb40a4f44f15\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/6fd24675188d354b1cad47462969afa2ab09d819\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/2f5e1565740490706332c06f36211d4ce0f88e62\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/a361c2c1da5dbb13ca67601cf961ab3ad68af383\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/483ae90d8f976f8339cf81066312e1329f2d3706\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T00:07:19.636Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-26586\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-02-22T20:41:19.395721Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-07-05T15:20:37.640Z\"}}], \"cna\": {\"title\": \"mlxsw: spectrum_acl_tcam: Fix stack corruption\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerability is reached through the rtnetlink/`tc filter add` path via the `sendmsg()` syscall on a netlink socket, requiring local system access. Network packets traversing the switch cannot reach the ACL group configuration code, which only runs on control-plane filter installation.\\nAC:L - The attacker deterministically forces more than 16 ACLs into one group by adding flower filters with decreasing priorities in an alternating key layout so consecutive filters cannot share a TCAM region \\u2014 the exact sequence the added selftest performs. There is no race, no timing window, and no dependence on unpredictable memory layout.\\nPR:L - `rtnetlink_rcv_msg` gates filter creation on CAP_NET_ADMIN, a delegated capability well short of full root that is routinely granted to network-management daemons and `--net=host --cap-add=NET_ADMIN` containers on the switch platforms where mlxsw is deployed. Such a semi-privileged context crosses a real boundary by smashing the kernel stack.\\nUI:N - The attacker installs the tc filters entirely on their own; no victim action, no mount, and no file open is involved. The overflow occurs synchronously inside the attacker\u0027s own syscall.\\nS:U - The corrupted memory is the kernel stack of the calling thread, and the impact stays within the kernel\u0027s own security authority. No hypervisor, IOMMU, or sandbox boundary is crossed.\\nC:H - Each out-of-bounds iteration read-modify-writes stack memory beyond the 112-byte `pagt_pl` buffer, and the resulting corruption of saved registers and the return address is the kind of memory corruption that can be steered toward disclosing kernel memory. Per the higher-severity rule for out-of-bounds writes on the kernel stack, this is scored High.\\nI:H - This is an out-of-bounds write that walks linearly past the end of a fixed 112-byte stack buffer, overwriting the stack canary, saved registers, and return address with values partially controlled by the attacker (region IDs and the `multi` bit). Out-of-bounds writes into a kernel stack frame are treated as High integrity impact.\\nA:H - The documented and reproducible outcome is `Kernel panic - not syncing: stack-protector: Kernel stack is corrupted`, an unconditional panic that takes down the entire switch. The condition is triggered on demand and repeatably.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"c3ab435466d5109b2c7525a3b90107d4d9e918fc\", \"lessThan\": \"56750ea5d15426b5f307554e7699e8b5f76c3182\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c3ab435466d5109b2c7525a3b90107d4d9e918fc\", \"lessThan\": \"348112522a35527c5bcba933b9fefb40a4f44f15\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c3ab435466d5109b2c7525a3b90107d4d9e918fc\", \"lessThan\": \"6fd24675188d354b1cad47462969afa2ab09d819\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c3ab435466d5109b2c7525a3b90107d4d9e918fc\", \"lessThan\": \"2f5e1565740490706332c06f36211d4ce0f88e62\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c3ab435466d5109b2c7525a3b90107d4d9e918fc\", \"lessThan\": \"a361c2c1da5dbb13ca67601cf961ab3ad68af383\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c3ab435466d5109b2c7525a3b90107d4d9e918fc\", \"lessThan\": \"483ae90d8f976f8339cf81066312e1329f2d3706\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/net/ethernet/mellanox/mlxsw/spectrum_acl_tcam.c\", \"tools/testing/selftests/drivers/net/mlxsw/spectrum-2/tc_flower.sh\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.19\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.19\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.10.209\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.148\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.79\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.14\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.7.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/net/ethernet/mellanox/mlxsw/spectrum_acl_tcam.c\", \"tools/testing/selftests/drivers/net/mlxsw/spectrum-2/tc_flower.sh\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/56750ea5d15426b5f307554e7699e8b5f76c3182\"}, {\"url\": \"https://git.kernel.org/stable/c/348112522a35527c5bcba933b9fefb40a4f44f15\"}, {\"url\": \"https://git.kernel.org/stable/c/6fd24675188d354b1cad47462969afa2ab09d819\"}, {\"url\": \"https://git.kernel.org/stable/c/2f5e1565740490706332c06f36211d4ce0f88e62\"}, {\"url\": \"https://git.kernel.org/stable/c/a361c2c1da5dbb13ca67601cf961ab3ad68af383\"}, {\"url\": \"https://git.kernel.org/stable/c/483ae90d8f976f8339cf81066312e1329f2d3706\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nmlxsw: spectrum_acl_tcam: Fix stack corruption\\n\\nWhen tc filters are first added to a net device, the corresponding local\\nport gets bound to an ACL group in the device. The group contains a list\\nof ACLs. In turn, each ACL points to a different TCAM region where the\\nfilters are stored. During forwarding, the ACLs are sequentially\\nevaluated until a match is found.\\n\\nOne reason to place filters in different regions is when they are added\\nwith decreasing priorities and in an alternating order so that two\\nconsecutive filters can never fit in the same region because of their\\nkey usage.\\n\\nIn Spectrum-2 and newer ASICs the firmware started to report that the\\nmaximum number of ACLs in a group is more than 16, but the layout of the\\nregister that configures ACL groups (PAGT) was not updated to account\\nfor that. It is therefore possible to hit stack corruption [1] in the\\nrare case where more than 16 ACLs in a group are required.\\n\\nFix by limiting the maximum ACL group size to the minimum between what\\nthe firmware reports and the maximum ACLs that fit in the PAGT register.\\n\\nAdd a test case to make sure the machine does not crash when this\\ncondition is hit.\\n\\n[1]\\nKernel panic - not syncing: stack-protector: Kernel stack is corrupted in: mlxsw_sp_acl_tcam_group_update+0x116/0x120\\n[...]\\n dump_stack_lvl+0x36/0x50\\n panic+0x305/0x330\\n __stack_chk_fail+0x15/0x20\\n mlxsw_sp_acl_tcam_group_update+0x116/0x120\\n mlxsw_sp_acl_tcam_group_region_attach+0x69/0x110\\n mlxsw_sp_acl_tcam_vchunk_get+0x492/0xa20\\n mlxsw_sp_acl_tcam_ventry_add+0x25/0xe0\\n mlxsw_sp_acl_rule_add+0x47/0x240\\n mlxsw_sp_flower_replace+0x1a9/0x1d0\\n tc_setup_cb_add+0xdc/0x1c0\\n fl_hw_replace_filter+0x146/0x1f0\\n fl_change+0xc17/0x1360\\n tc_new_tfilter+0x472/0xb90\\n rtnetlink_rcv_msg+0x313/0x3b0\\n netlink_rcv_skb+0x58/0x100\\n netlink_unicast+0x244/0x390\\n netlink_sendmsg+0x1e4/0x440\\n ____sys_sendmsg+0x164/0x260\\n ___sys_sendmsg+0x9a/0xe0\\n __sys_sendmsg+0x7a/0xc0\\n do_syscall_64+0x40/0xe0\\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.209\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.148\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.79\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.14\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.2\", \"versionStartIncluding\": \"4.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8\", \"versionStartIncluding\": \"4.19\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:26:05.421Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-26586\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:26:05.421Z\", \"dateReserved\": \"2024-02-19T14:20:24.125Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-02-22T16:13:31.796Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…