Linux Kernel Vulnerability in Mellanox mlx5e Driver
CVE-2026-74698
What is CVE-2026-74698?
A vulnerability within the Mellanox mlx5e driver of the Linux kernel leads to improper queue management during the reactivation of send queues. Specifically, the mlx5e_queue_start function can reactivate all channels while failing to reset the bandwidth queue limits accurately. This mismanagement can cause an erroneous overcharging of in-flight transmit work queue entries, ultimately leading to application crashes or unexpected behavior due to the triggered kernel BUG_ON in dql_completed. To mitigate this, it is crucial to implement a reset of the bandwidth queue limit only when the send queue has no outstanding bytes in flight.
Affected Version(s)
Linux b2588ea40ec9472688289c1a644627c0f4a1f33f < 88664c48d7d1eca8e1ac92da85c89c26af741cf1
Linux b2588ea40ec9472688289c1a644627c0f4a1f33f
Linux b2588ea40ec9472688289c1a644627c0f4a1f33f