CVE-2026-72342 (GCVE-0-2026-72342)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-17 05:43
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix HV VHCA stats agent registration race
mlx5e_hv_vhca_stats_create() registers the stats agent through
mlx5_hv_vhca_agent_create(). The helper publishes the agent in
hv_vhca->agents[type] under agents_lock and immediately schedules an
asynchronous control invalidation on the HV VHCA workqueue before
returning to mlx5e.
The asynchronous invalidation invokes the control agent's invalidate
callback, which reads the hypervisor control block and forwards the
command to mlx5e_hv_vhca_stats_control(). That callback may either:
- call cancel_delayed_work_sync(&priv->stats_agent.work), or
- call queue_delayed_work(priv->wq, &sagent->work, sagent->delay).
However, the delayed_work and priv->stats_agent.agent are only
initialized after mlx5_hv_vhca_agent_create() returns to mlx5e:
agent = mlx5_hv_vhca_agent_create(...); /* publish + invalidate */
...
priv->stats_agent.agent = agent; /* too late */
INIT_DELAYED_WORK(&priv->stats_agent.work, ...); /* too late */
If the asynchronous control path runs before the two assignments
above, it can:
- Operate on an uninitialized delayed_work whose timer.function is
NULL. queue_delayed_work() calls add_timer() unconditionally, so
when the timer expires the timer softirq invokes a NULL function
pointer.
- Re-initialize the timer later through INIT_DELAYED_WORK() while
the timer is already enqueued in the timer wheel, corrupting the
hlist (entry.pprev cleared while the previous bucket node still
points at this entry).
- When the worker eventually runs, mlx5e_hv_vhca_stats_work() reads
sagent->agent (NULL) and dereferences it inside
mlx5_hv_vhca_agent_write().
Fix this by:
- Initializing priv->stats_agent.work before invoking
mlx5_hv_vhca_agent_create(), so the work is always in a valid
state when the control callback observes it.
- Adding a struct mlx5_hv_vhca_agent **ctx_update out-parameter
to mlx5_hv_vhca_agent_create(). The helper writes the agent
pointer to *ctx_update before publishing into hv_vhca->agents[]
and triggering the agents_update flow, so any callback
subsequently invoked from that flow already sees a valid
priv->stats_agent.agent. This avoids having the control
callback participate in agent initialization.
While at it, access priv->stats_agent.agent with
READ_ONCE()/WRITE_ONCE() for the cross-CPU access with the worker, and
clear priv->stats_agent.buf on the agent_create() failure path.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cef35af34d6dc3792333075115c7deb7062b6e18 Version: cef35af34d6dc3792333075115c7deb7062b6e18 Version: cef35af34d6dc3792333075115c7deb7062b6e18 Version: cef35af34d6dc3792333075115c7deb7062b6e18 Version: cef35af34d6dc3792333075115c7deb7062b6e18 Version: cef35af34d6dc3792333075115c7deb7062b6e18 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c",
"drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.c",
"drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b0fd6d3bb06182f19f3b59a53f57b5098b99048a",
"status": "affected",
"version": "cef35af34d6dc3792333075115c7deb7062b6e18",
"versionType": "git"
},
{
"lessThan": "24c77044cdfcf5b8b2e9f3b620d8b9aa392d9add",
"status": "affected",
"version": "cef35af34d6dc3792333075115c7deb7062b6e18",
"versionType": "git"
},
{
"lessThan": "e8fc3304cb67fb1d7d11ff9ef9abd5fb64e7e1d5",
"status": "affected",
"version": "cef35af34d6dc3792333075115c7deb7062b6e18",
"versionType": "git"
},
{
"lessThan": "60fddda7207d81fea71463abd403f0b10f74f2e1",
"status": "affected",
"version": "cef35af34d6dc3792333075115c7deb7062b6e18",
"versionType": "git"
},
{
"lessThan": "f5677797b094c3ec5fb350eb8ea7710b88a3d018",
"status": "affected",
"version": "cef35af34d6dc3792333075115c7deb7062b6e18",
"versionType": "git"
},
{
"lessThan": "89b25b5f46f488ea3b29b3444864c76944c9075b",
"status": "affected",
"version": "cef35af34d6dc3792333075115c7deb7062b6e18",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c",
"drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.c",
"drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix HV VHCA stats agent registration race\n\nmlx5e_hv_vhca_stats_create() registers the stats agent through\nmlx5_hv_vhca_agent_create(). The helper publishes the agent in\nhv_vhca-\u003eagents[type] under agents_lock and immediately schedules an\nasynchronous control invalidation on the HV VHCA workqueue before\nreturning to mlx5e.\n\nThe asynchronous invalidation invokes the control agent\u0027s invalidate\ncallback, which reads the hypervisor control block and forwards the\ncommand to mlx5e_hv_vhca_stats_control(). That callback may either:\n\n - call cancel_delayed_work_sync(\u0026priv-\u003estats_agent.work), or\n - call queue_delayed_work(priv-\u003ewq, \u0026sagent-\u003ework, sagent-\u003edelay).\n\nHowever, the delayed_work and priv-\u003estats_agent.agent are only\ninitialized after mlx5_hv_vhca_agent_create() returns to mlx5e:\n\n agent = mlx5_hv_vhca_agent_create(...); /* publish + invalidate */\n ...\n priv-\u003estats_agent.agent = agent; /* too late */\n INIT_DELAYED_WORK(\u0026priv-\u003estats_agent.work, ...); /* too late */\n\nIf the asynchronous control path runs before the two assignments\nabove, it can:\n\n - Operate on an uninitialized delayed_work whose timer.function is\n NULL. queue_delayed_work() calls add_timer() unconditionally, so\n when the timer expires the timer softirq invokes a NULL function\n pointer.\n - Re-initialize the timer later through INIT_DELAYED_WORK() while\n the timer is already enqueued in the timer wheel, corrupting the\n hlist (entry.pprev cleared while the previous bucket node still\n points at this entry).\n - When the worker eventually runs, mlx5e_hv_vhca_stats_work() reads\n sagent-\u003eagent (NULL) and dereferences it inside\n mlx5_hv_vhca_agent_write().\n\nFix this by:\n\n - Initializing priv-\u003estats_agent.work before invoking\n mlx5_hv_vhca_agent_create(), so the work is always in a valid\n state when the control callback observes it.\n - Adding a struct mlx5_hv_vhca_agent **ctx_update out-parameter\n to mlx5_hv_vhca_agent_create(). The helper writes the agent\n pointer to *ctx_update before publishing into hv_vhca-\u003eagents[]\n and triggering the agents_update flow, so any callback\n subsequently invoked from that flow already sees a valid\n priv-\u003estats_agent.agent. This avoids having the control\n callback participate in agent initialization.\n\nWhile at it, access priv-\u003estats_agent.agent with\nREAD_ONCE()/WRITE_ONCE() for the cross-CPU access with the worker, and\nclear priv-\u003estats_agent.buf on the agent_create() failure path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in mlx5e HV VHCA stats agent registration during mlx5e driver attach on Hyper-V/Azure mlx5 NICs; it is reached via the VMBus PCI config back-channel and driver init, not via remote network packet handling.\nAC:L - mlx5_hv_vhca_agent_create() always queues asynchronous control invalidation before returning; on SMP hosts the workqueue races unfinished delayed_work/agent setup, and the path can be re-triggered via devlink reload or driver reattach.\nPR:N - No guest privileges are required: the race opens during normal mlx5e attach at boot/resume on CONFIG_PCI_HYPERV_INTERFACE systems, and the hypervisor can drive the control callback via the VHCA control block without guest credentials.\nUI:N - No user or administrator action is needed beyond normal VM boot and mlx5 driver initialization; exploitation does not depend on a victim opening files, mounting filesystems, or other interactive steps.\nS:U - Memory corruption and kernel crashes are confined to the guest kernel running mlx5e; the bug does not cross VM/host, IOMMU, or other security boundaries into a separate authority.\nC:H - The race can corrupt the kernel timer wheel hlist, invoke a NULL timer callback, or dereference a NULL agent during mlx5_hv_vhca_agent_write(), providing serious kernel memory corruption or disclosure primitives.\nI:H - Timer wheel hlist corruption and operating on uninitialized delayed_work structures are exploitable memory corruption that can be leveraged for arbitrary kernel writes or control-flow hijacking, not merely a bounded fault.\nA:H - Exploitation causes kernel oops/panic from NULL function-pointer timer callbacks, corrupted timer lists, or NULL agent dereferences, reliably denying availability of the affected system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:43:00.745Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b0fd6d3bb06182f19f3b59a53f57b5098b99048a"
},
{
"url": "https://git.kernel.org/stable/c/24c77044cdfcf5b8b2e9f3b620d8b9aa392d9add"
},
{
"url": "https://git.kernel.org/stable/c/e8fc3304cb67fb1d7d11ff9ef9abd5fb64e7e1d5"
},
{
"url": "https://git.kernel.org/stable/c/60fddda7207d81fea71463abd403f0b10f74f2e1"
},
{
"url": "https://git.kernel.org/stable/c/f5677797b094c3ec5fb350eb8ea7710b88a3d018"
},
{
"url": "https://git.kernel.org/stable/c/89b25b5f46f488ea3b29b3444864c76944c9075b"
}
],
"title": "net/mlx5e: Fix HV VHCA stats agent registration race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72342",
"datePublished": "2026-08-15T05:55:48.412Z",
"dateReserved": "2026-08-09T03:40:39.920Z",
"dateUpdated": "2026-08-17T05:43:00.745Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…