Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64472

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> vfio/mlx5: Fix racy bitfields and tighten struct layout<br /> <br /> Bitfield operations are not atomic, they use a read-modify-write<br /> pattern, therefore we should be careful not to pack bitfields that<br /> can be concurrently updated into the same storage unit.<br /> <br /> This split takes a binary approach: flags that are only modified<br /> pre/post open/close remain bitfields, flags modified from user<br /> action, including actions that reach across to another device (ex.<br /> reset) use dedicated storage units.<br /> <br /> Note mlx5_vhca_page_tracker.status is relocated to fill the alignment<br /> hole this split exposes.<br /> <br /> Bitfield justifications:<br /> <br /> migrate_cap: written only in mlx5vf_cmd_set_migratable() at probe<br /> chunk_mode: written only in mlx5vf_cmd_set_migratable() at probe<br /> mig_state_cap: written only in mlx5vf_cmd_set_migratable() at probe<br /> <br /> Dedicated storage units:<br /> <br /> mdev_detach: written in the VF attach/detach event notifier<br /> mlx5fv_vf_event() at runtime<br /> log_active: written in mlx5vf_start_page_tracker()/<br /> mlx5vf_stop_page_tracker() during runtime dirty tracking<br /> deferred_reset: written in mlx5vf_state_mutex_unlock()/<br /> mlx5vf_pci_aer_reset_done() during runtime reset handling<br /> is_err: set by tracker error handling and dirty-log polling at runtime<br /> object_changed: set by tracker event handling and cleared by dirty-log<br /> polling at runtime

Impacto