Database/Firmware, BMC & network fabric
Linux kernel mlx5_core eswitch ingress ACL: TENANT ISOLATION: the eswitch ingress ACL
Impact
TENANT ISOLATION: the eswitch ingress ACL - the table that enforces per-VF ingress policy - is only created when vport metadata match or prio tag is on. Turn vport metadata match off via devlink and bring up an active-backup LAG, and the driver panics on a missing ingress ACL. Beyond the crash, this is a config in which the VF ingress enforcement structure is simply absent when the driver expects it.
Who can reach it
Requires an administrator to have set esw_port_metadata=false via devlink and to be running active-backup LAG. Not tenant-triggered, but it is a realistic operator configuration on bonded ConnectX hosts.
What to do
Upgrade the host kernel to 6.10 or a stable backport (6.1.98, 6.6.39, 6.9.9). Rolling reboot. Immediate config-level mitigation: keep esw_port_metadata at its default (true) on LAG hosts - a devlink change, no reboot.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.