CVE-2026-43467
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/05/2026
Last modified:
12/05/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net/mlx5: Fix crash when moving to switchdev mode<br />
<br />
When moving to switchdev mode when the device doesn&#39;t support IPsec,<br />
we try to clean up the IPsec resources anyway which causes the crash<br />
below, fix that by correctly checking for IPsec support before trying<br />
to clean up its resources.<br />
<br />
[27642.515799] WARNING: arch/x86/mm/fault.c:1276 at<br />
do_user_addr_fault+0x18a/0x680, CPU#4: devlink/6490<br />
[27642.517159] Modules linked in: xt_conntrack xt_MASQUERADE<br />
ip6table_nat ip6table_filter ip6_tables iptable_nat nf_nat xt_addrtype<br />
rpcsec_gss_krb5 auth_rpcgss oid_registry overlay mlx5_fwctl nfnetlink<br />
zram zsmalloc mlx5_ib fuse rpcrdma rdma_ucm ib_uverbs ib_iser libiscsi<br />
scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm mlx5_core<br />
ib_core<br />
[27642.521358] CPU: 4 UID: 0 PID: 6490 Comm: devlink Not tainted<br />
6.19.0-rc5_for_upstream_min_debug_2026_01_14_16_47 #1 NONE<br />
[27642.522923] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS<br />
rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014<br />
[27642.524528] RIP: 0010:do_user_addr_fault+0x18a/0x680<br />
[27642.525362] Code: ff 0f 84 75 03 00 00 48 89 ee 4c 89 e7 e8 5e b9 22<br />
00 49 89 c0 48 85 c0 0f 84 a8 02 00 00 f7 c3 60 80 00 00 74 22 31 c9 eb<br />
ae 0b 48 83 c4 10 48 89 ea 48 89 de 4c 89 f7 5b 5d 41 5c 41 5d<br />
41<br />
[27642.528166] RSP: 0018:ffff88810770f6b8 EFLAGS: 00010046<br />
[27642.529038] RAX: 0000000000000000 RBX: 0000000000000002 RCX:<br />
ffff88810b980f00<br />
[27642.530158] RDX: 00000000000000a0 RSI: 0000000000000002 RDI:<br />
ffff88810770f728<br />
[27642.531270] RBP: 00000000000000a0 R08: 0000000000000000 R09:<br />
0000000000000000<br />
[27642.532383] R10: 0000000000000000 R11: 0000000000000000 R12:<br />
ffff888103f3c4c0<br />
[27642.533499] R13: 0000000000000000 R14: ffff88810770f728 R15:<br />
0000000000000000<br />
[27642.534614] FS: 00007f197c741740(0000) GS:ffff88856a94c000(0000)<br />
knlGS:0000000000000000<br />
[27642.535915] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033<br />
[27642.536858] CR2: 00000000000000a0 CR3: 000000011334c003 CR4:<br />
0000000000172eb0<br />
[27642.537982] Call Trace:<br />
[27642.538466] <br />
[27642.538907] exc_page_fault+0x76/0x140<br />
[27642.539583] asm_exc_page_fault+0x22/0x30<br />
[27642.540282] RIP: 0010:_raw_spin_lock_irqsave+0x10/0x30<br />
[27642.541134] Code: 07 85 c0 75 11 ba ff 00 00 00 f0 0f b1 17 75 06 b8<br />
01 00 00 00 c3 31 c0 c3 90 0f 1f 44 00 00 53 9c 5b fa 31 c0 ba 01 00 00<br />
00 0f b1 17 75 05 48 89 d8 5b c3 89 c6 e8 7e 02 00 00 48 89 d8<br />
5b<br />
[27642.543936] RSP: 0018:ffff88810770f7d8 EFLAGS: 00010046<br />
[27642.544803] RAX: 0000000000000000 RBX: 0000000000000202 RCX:<br />
ffff888113ad96d8<br />
[27642.545916] RDX: 0000000000000001 RSI: ffff88810770f818 RDI:<br />
00000000000000a0<br />
[27642.547027] RBP: 0000000000000098 R08: 0000000000000400 R09:<br />
ffff88810b980f00<br />
[27642.548140] R10: 0000000000000001 R11: ffff888101845a80 R12:<br />
00000000000000a8<br />
[27642.549263] R13: ffffffffa02a9060 R14: 00000000000000a0 R15:<br />
ffff8881130d8a40<br />
[27642.550379] complete_all+0x20/0x90<br />
[27642.551010] mlx5e_ipsec_disable_events+0xb6/0xf0 [mlx5_core]<br />
[27642.552022] mlx5e_nic_disable+0x12d/0x220 [mlx5_core]<br />
[27642.552929] mlx5e_detach_netdev+0x66/0xf0 [mlx5_core]<br />
[27642.553822] mlx5e_netdev_change_profile+0x5b/0x120 [mlx5_core]<br />
[27642.554821] mlx5e_vport_rep_load+0x419/0x590 [mlx5_core]<br />
[27642.555757] ? xa_load+0x53/0x90<br />
[27642.556361] __esw_offloads_load_rep+0x54/0x70 [mlx5_core]<br />
[27642.557328] mlx5_esw_offloads_rep_load+0x45/0xd0 [mlx5_core]<br />
[27642.558320] esw_offloads_enable+0xb4b/0xc90 [mlx5_core]<br />
[27642.559247] mlx5_eswitch_enable_locked+0x34e/0x4f0 [mlx5_core]<br />
[27642.560257] ? mlx5_rescan_drivers_locked+0x222/0x2d0 [mlx5_core]<br />
[27642.561284] mlx5_devlink_eswitch_mode_set+0x5ac/0x9c0 [mlx5_core]<br />
[27642.562334] ? devlink_rate_set_ops_supported+0x21/0x3a0<br />
[27642.563220] devlink_nl_eswitch_set_doit+0x67/0xe0<br />
[27642.564026] genl_family_rcv_msg_doit+0xe0/0x130<br />
[27642.564816] genl_rcv_msg+0x183/0x290<br />
[27642.565466] ? __devlink_nl_pre_doit.isra.0+0x160/0x160<br />
[27642.566329] ? d<br />
---truncated---



