SB2026011430 - Use-after-free in Linux kernel mellanox mlxsw driver
Published: January 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2025-68801)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the mlxsw_sp_neigh_entry_alloc(), mlxsw_sp_nexthop_dead_neigh_replace(), mlxsw_sp_nexthop_neigh_init() and mlxsw_sp_nexthop_neigh_fini() functions in drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4a3c569005f42ab5e5b2ad637132a33bf102cc08
- https://git.kernel.org/stable/c/675c5aeadf6472672c472dc0f26401e4fcfbf254
- https://git.kernel.org/stable/c/8b0e69763ef948fb872a7767df4be665d18f5fd4
- https://git.kernel.org/stable/c/c437fbfd4382412598cdda1f8e2881b523668cc2
- https://git.kernel.org/stable/c/ed8141b206bdcfd5d0b92c90832eeb77b7a60a0a