CVE-2025-38127 Information
Description
In the Linux kernel the following vulnerability has been resolved:
ice: fix Tx scheduler error handling in XDP callback
When the XDP program is loaded the XDP callback adds new Tx queues. This means that the callback must update the Tx scheduler with the new queue number. In the event of a Tx scheduler failure the XDP callback should also fail and roll back any changes previously made for XDP preparation.
The previous implementation had a bug that not all changes made by the XDP callback were rolled back. This caused the crash with the following call trace:
[ +9.549584] ice 0000:ca:00.0: Failed VSI LAN queue config for XDP error: -5 [ +0.382335] Oops: general protection fault probably for non-canonical address 0x50a2250a90495525: 0000 [1] SMP NOPTI [ +0.010710] CPU: 103 UID: 0 PID: 0 Comm: swapper/103 Not tainted 6.14.0-net-next-mar-31+ 14 PREEMPT(voluntary) [ +0.010175] Hardware name: Intel Corporation M50CYP2SBSTD/M50CYP2SBSTD BIOS SE5C620.86B.01.01.0005.2202160810 02/16/2022 [ +0.010946] RIP: 0010:__ice_update_sample+0x39/0xe0 [ice]
[…]
[ +0.002715] Call Trace:
[ +0.002452]
Fix this by performing the missing unmapping of XDP queues from q_vectors and setting the XDP rings pointer back to NULL after all those queues are released. Also add an immediate exit from the XDP callback in case of ring preparation failure.
Reference
https://git.kernel.org/stable/c/0153f36041b8e52019ebfa8629c13bf8f9b0a951 https://git.kernel.org/stable/c/0e061abaad1498c5b76c10c594d4359ceb6b9145 https://git.kernel.org/stable/c/1d3c5d0dec6797eca3a861dab0816fa9505d9c3e https://git.kernel.org/stable/c/276849954d7cbe6eec827b21fe2df43f9bf07011
Related CNNVD
CNNVD-202507-213 (Published: 2025-07-03)
Share on: