SB2026090566 - Race condition in Linux kernel hw mlx5 driver
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-80880)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a race condition.
The vulnerability exists due to a race condition in implicit ODP memory region re-registration when reregistering an implicit ODP memory region without specifying a translation. A local user can reregister an implicit ODP memory region to trigger a race condition.
The race involves implicit child mkeys accessing the memory region's protection domain.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/5d02b9a2efd11d28d2a8feac7769686b1b871d9c
- https://git.kernel.org/stable/c/94f7e50eb6b2ce7fbd9aeac1db22460d2013a3fb
- https://git.kernel.org/stable/c/cbc9982c8573fb9e35040063aa78c8ebe768a1ff
- https://git.kernel.org/stable/c/d4f84bfa089fe71f775d25beb29303e844494c25
- https://git.kernel.org/stable/c/eb7cb798e563b3f3b3baeb9cc6f7455764267e50
- https://git.kernel.org/stable/c/ee7a8335069150c3f1893a697ab30bbeca00d796
- https://git.kernel.org/stable/c/ee914ef54a7e707453ecb43eb30fb0a5c6dd0d69