SB20250422140 - Buffer overflow in Linux kernel hw mlx5 driver
Published: April 22, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2025-22091)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the create_mkey_callback(), alloc_cacheable_mr(), reg_create() and create_real_mr() functions in drivers/infiniband/hw/mlx5/mr.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/01fd737776ca0f17a96d83cd7f0840ce130b9a02
- https://git.kernel.org/stable/c/05b215d5e219c0228b9c7082ba9bcf176c576646
- https://git.kernel.org/stable/c/e0c09f639ca0e102f250df8787740c2013e9d1b3
- https://git.kernel.org/stable/c/f0c2427412b43cdf1b7b0944749ea17ddb97d5a5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.23
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.11
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14.2