CVE-2025-22086: RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow

Published Apr 16, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

RDMA/mlx5: Fix mlx5pollone() curqp update flow

When curqp isn't NULL, in order to avoid fetching the QP from the radix tree again we check if the next cqe QP is identical to the one we already have.

The bug however is that we are checking if the QP is identical by checking the QP number inside the CQE against the QP number inside the mlx5ibqp, but that's wrong since the QP number from the CQE is from FW so it should be matched against mlx5coreqp which is our FW QP number.

Otherwise we could use the wrong QP when handling a CQE which could cause the kernel trace below.

This issue is mainly noticeable over QPs 0 & 1, since for now they are the only QPs in our driver whereas the QP number inside mlx5ibqp doesn't match the QP number inside mlx5coreqp.

BUG: kernel NULL pointer dereference, address: 0000000000000012 #PF: supervisor read access in kernel mode #PF: errorcode(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP CPU: 0 UID: 0 PID: 7927 Comm: kworker/u62:1 Not tainted 6.14.0-rc3+ #189 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 Workqueue: ib-comp-unb-wq ibcqpollwork [ibcore] RIP: 0010:mlx5ibpollcq+0x4c7/0xd90 [mlx5ib] Code: 03 00 00 8d 58 ff 21 cb 66 39 d3 74 39 48 c7 c7 3c 89 6e a0 0f b7 db e8 b7 d2 b3 e0 49 8b 86 60 03 00 00 48 c7 c7 4a 89 6e a0 <0f> b7 5c 98 02 e8 9f d2 b3 e0 41 0f b7 86 78 03 00 00 83 e8 01 21 RSP: 0018:ffff88810511bd60 EFLAGS: 00010046 RAX: 0000000000000010 RBX: 0000000000000000 RCX: 0000000000000000 RDX: 0000000000000000 RSI: ffff88885fa1b3c0 RDI: ffffffffa06e894a RBP: 00000000000000b0 R08: 0000000000000000 R09: ffff88810511bc10 R10: 0000000000000001 R11: 0000000000000001 R12: ffff88810d593000 R13: ffff88810e579108 R14: ffff888105146000 R15: 00000000000000b0 FS: 0000000000000000(0000) GS:ffff88885fa00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000012 CR3: 00000001077e6001 CR4: 0000000000370eb0 Call Trace: <TASK> ? die+0x20/0x60 ? pagefaultoops+0x150/0x3e0 ? excpagefault+0x74/0x130 ? asmexcpagefault+0x22/0x30 ? mlx5ibpollcq+0x4c7/0xd90 [mlx5ib] ibprocesscq+0x5a/0x150 [ibcore] ibcqpollwork+0x31/0x90 [ibcore] processonework+0x169/0x320 workerthread+0x288/0x3a0 ? workbusy+0xb0/0xb0 kthread+0xd7/0x1f0 ? kthreadsonlinecpu+0x130/0x130 ? kthreadsonlinecpu+0x130/0x130 retfromfork+0x2d/0x50 ? kthreadsonlinecpu+0x130/0x130 retfromforkasm+0x11/0x20 </TASK>

Affected Software

9 affected components
Linux Linux kernel
Linux Linux kernel>=3.11<5.4.292
Linux Linux kernel>=5.5<5.10.236
Linux Linux kernel>=5.11<5.15.180
Linux Linux kernel>=5.16<6.1.134
Linux Linux kernel>=6.2<6.6.87
Linux Linux kernel>=6.7<6.12.23
Linux Linux kernel>=6.13<6.13.11
Linux Linux kernel>=6.14<6.14.2

Event History

Apr 16, 2025
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
DescriptionSeverity
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-22086?

CVE-2025-22086 has been identified as having a medium severity level due to its impact on kernel functionality.

2

What systems are affected by CVE-2025-22086?

CVE-2025-22086 affects the Linux kernel, specifically in implementations utilizing RDMA/mlx5.

3

How do I fix CVE-2025-22086?

To fix CVE-2025-22086, update your Linux kernel to the latest stable release that includes the patch for this vulnerability.

4

Is there a workaround for CVE-2025-22086?

Currently, there are no known workarounds for CVE-2025-22086, so patching is recommended.

5

When was CVE-2025-22086 resolved?

CVE-2025-22086 was resolved in a recent update to the Linux kernel, although specific dates may vary depending on the release.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203