All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race
Date: Sat, 15 Aug 2026 15:07:01 +0900	[thread overview]
Message-ID: <2026081510-CVE-2026-72342-0fc2@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: Fix HV VHCA stats agent registration race

mlx5e_hv_vhca_stats_create() registers the stats agent through
mlx5_hv_vhca_agent_create(). The helper publishes the agent in
hv_vhca->agents[type] under agents_lock and immediately schedules an
asynchronous control invalidation on the HV VHCA workqueue before
returning to mlx5e.

The asynchronous invalidation invokes the control agent's invalidate
callback, which reads the hypervisor control block and forwards the
command to mlx5e_hv_vhca_stats_control(). That callback may either:

  - call cancel_delayed_work_sync(&priv->stats_agent.work), or
  - call queue_delayed_work(priv->wq, &sagent->work, sagent->delay).

However, the delayed_work and priv->stats_agent.agent are only
initialized after mlx5_hv_vhca_agent_create() returns to mlx5e:

    agent = mlx5_hv_vhca_agent_create(...);   /* publish + invalidate */
    ...
    priv->stats_agent.agent = agent;          /* too late */
    INIT_DELAYED_WORK(&priv->stats_agent.work, ...); /* too late */

If the asynchronous control path runs before the two assignments
above, it can:

  - Operate on an uninitialized delayed_work whose timer.function is
    NULL. queue_delayed_work() calls add_timer() unconditionally, so
    when the timer expires the timer softirq invokes a NULL function
    pointer.
  - Re-initialize the timer later through INIT_DELAYED_WORK() while
    the timer is already enqueued in the timer wheel, corrupting the
    hlist (entry.pprev cleared while the previous bucket node still
    points at this entry).
  - When the worker eventually runs, mlx5e_hv_vhca_stats_work() reads
    sagent->agent (NULL) and dereferences it inside
    mlx5_hv_vhca_agent_write().

Fix this by:

  - Initializing priv->stats_agent.work before invoking
    mlx5_hv_vhca_agent_create(), so the work is always in a valid
    state when the control callback observes it.
  - Adding a struct mlx5_hv_vhca_agent **ctx_update out-parameter
    to mlx5_hv_vhca_agent_create(). The helper writes the agent
    pointer to *ctx_update before publishing into hv_vhca->agents[]
    and triggering the agents_update flow, so any callback
    subsequently invoked from that flow already sees a valid
    priv->stats_agent.agent. This avoids having the control
    callback participate in agent initialization.

While at it, access priv->stats_agent.agent with
READ_ONCE()/WRITE_ONCE() for the cross-CPU access with the worker, and
clear priv->stats_agent.buf on the agent_create() failure path.

The Linux kernel CVE team has assigned CVE-2026-72342 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.4 with commit cef35af34d6dc3792333075115c7deb7062b6e18 and fixed in 6.1.178 with commit b0fd6d3bb06182f19f3b59a53f57b5098b99048a
	Issue introduced in 5.4 with commit cef35af34d6dc3792333075115c7deb7062b6e18 and fixed in 6.6.145 with commit 24c77044cdfcf5b8b2e9f3b620d8b9aa392d9add
	Issue introduced in 5.4 with commit cef35af34d6dc3792333075115c7deb7062b6e18 and fixed in 6.12.97 with commit e8fc3304cb67fb1d7d11ff9ef9abd5fb64e7e1d5
	Issue introduced in 5.4 with commit cef35af34d6dc3792333075115c7deb7062b6e18 and fixed in 6.18.40 with commit 60fddda7207d81fea71463abd403f0b10f74f2e1
	Issue introduced in 5.4 with commit cef35af34d6dc3792333075115c7deb7062b6e18 and fixed in 7.1.5 with commit f5677797b094c3ec5fb350eb8ea7710b88a3d018
	Issue introduced in 5.4 with commit cef35af34d6dc3792333075115c7deb7062b6e18 and fixed in 7.2-rc3 with commit 89b25b5f46f488ea3b29b3444864c76944c9075b

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-72342
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c
	drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.c
	drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.h


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/b0fd6d3bb06182f19f3b59a53f57b5098b99048a
	https://git.kernel.org/stable/c/24c77044cdfcf5b8b2e9f3b620d8b9aa392d9add
	https://git.kernel.org/stable/c/e8fc3304cb67fb1d7d11ff9ef9abd5fb64e7e1d5
	https://git.kernel.org/stable/c/60fddda7207d81fea71463abd403f0b10f74f2e1
	https://git.kernel.org/stable/c/f5677797b094c3ec5fb350eb8ea7710b88a3d018
	https://git.kernel.org/stable/c/89b25b5f46f488ea3b29b3444864c76944c9075b

                 reply	other threads:[~2026-08-15  6:23 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026081510-CVE-2026-72342-0fc2@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.