Database/Kernel, userspace & hypervisor
Linux kernel mlx5_core kTLS RX offload: TLS RX resync list corruption: entries are moved by the resync handler
Impact
TLS RX resync list corruption: entries are moved by the resync handler while still in use in NAPI, corrupting the list from the receive softirq. Remote and unauthenticated on any node using mlx5 hardware kTLS RX offload.
Who can reach it
Remote sender over a TLS connection handled by mlx5 kTLS RX offload, able to trigger resync conditions (out-of-order or retransmitted TLS records).
What to do
Upgrade the host kernel to 5.16 or the 5.15.5 stable backport. Rolling reboot. Interim: disable kTLS RX offload (ethtool -K <dev> tls-hw-rx-offload off) as a live config change.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.