CVE-2024-26586: mlxsw: spectrum_acl_tcam: Fix stack corruption

Published Feb 22, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

mlxsw: spectrumacltcam: Fix stack corruption

When tc filters are first added to a net device, the corresponding local port gets bound to an ACL group in the device. The group contains a list of ACLs. In turn, each ACL points to a different TCAM region where the filters are stored. During forwarding, the ACLs are sequentially evaluated until a match is found.

One reason to place filters in different regions is when they are added with decreasing priorities and in an alternating order so that two consecutive filters can never fit in the same region because of their key usage.

In Spectrum-2 and newer ASICs the firmware started to report that the maximum number of ACLs in a group is more than 16, but the layout of the register that configures ACL groups (PAGT) was not updated to account for that. It is therefore possible to hit stack corruption [1] in the rare case where more than 16 ACLs in a group are required.

Fix by limiting the maximum ACL group size to the minimum between what the firmware reports and the maximum ACLs that fit in the PAGT register.

Add a test case to make sure the machine does not crash when this condition is hit.

[1] Kernel panic - not syncing: stack-protector: Kernel stack is corrupted in: mlxswspacltcamgroupupdate+0x116/0x120 [...] dumpstacklvl+0x36/0x50 panic+0x305/0x330 stackchkfail+0x15/0x20 mlxswspacltcamgroupupdate+0x116/0x120 mlxswspacltcamgroupregionattach+0x69/0x110 mlxswspacltcamvchunkget+0x492/0xa20 mlxswspacltcamventryadd+0x25/0xe0 mlxswspaclruleadd+0x47/0x240 mlxswspflowerreplace+0x1a9/0x1d0 tcsetupcbadd+0xdc/0x1c0 flhwreplacefilter+0x146/0x1f0 flchange+0xc17/0x1360 tcnewtfilter+0x472/0xb90 rtnetlinkrcvmsg+0x313/0x3b0 netlinkrcvskb+0x58/0x100 netlinkunicast+0x244/0x390 netlinksendmsg+0x1e4/0x440 syssendmsg+0x164/0x260 syssendmsg+0x9a/0xe0 syssendmsg+0x7a/0xc0 dosyscall64+0x40/0xe0 entrySYSCALL64afterhwframe+0x63/0x6b

Other sources

Linux Kernel is vulnerable to a denial of service, caused by a stack corruption in mlxsw: spectrumacltcam. A local attacker could exploit this vulnerability to cause a kernel panic.

IBM

Affected Software

16 affected componentsFixes available
redhat/kernel<6.8
6.8
redhat/kernel<6.7.2
6.7.2
redhat/kernel<6.6.14
6.6.14
redhat/kernel<5.15.148
5.15.148
redhat/kernel<5.10.209
5.10.209
redhat/kernel<5.4.268
5.4.268
Linux Linux kernel>=4.19.0<5.10.209
Linux Linux kernel>=5.11.0<5.15.148
Linux Linux kernel>=5.16.0<6.1.79
Linux Linux kernel>=6.2.0<6.6.14
Linux Linux kernel>=6.7.0<6.7.2
IBM Security Verify Governance<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager Software Stack<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager Virtual Appliance<=ISVG 10.0.2
IBM Security Verify Governance Identity Manager Container<=ISVG 10.0.2
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Event History

Feb 22, 2024
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
Description
Feb 23, 2024
Data Sourced
via Red Hat·01:45 PM
DescriptionSeverityAffected Software
Apr 9, 2024
Data Sourced
via Launchpad·02:37 PM
Description
Apr 29, 2025
Data Sourced
via Ubuntu·06:12 AM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-26586?

CVE-2024-26586 has been classified as a medium severity vulnerability due to the potential for stack corruption.

2

How do I fix CVE-2024-26586?

To mitigate CVE-2024-26586, update your Linux kernel to version 6.8 or apply patches that address this vulnerability.

3

Which versions of the Linux kernel are affected by CVE-2024-26586?

CVE-2024-26586 affects Linux kernel versions prior to 6.8, as well as several earlier versions.

4

What components are impacted by CVE-2024-26586?

CVE-2024-26586 impacts the mlxsw spectrum ACL TCAM functionality within the Linux kernel.

5

Has CVE-2024-26586 been resolved in any kernels?

Yes, CVE-2024-26586 has been resolved in kernel versions 6.8 and patched versions of earlier kernels, such as 6.7.2 and 5.15.148.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203