GPU VulnDB

Database/Firmware, BMC & network fabric

Linux kernel mlxsw (Spectrum switch router, neighbour table): The driver stored neighbour pointers without holding

CVE-2025-68801Firmware, BMC & network fabricmlxsw spectrum_router fix neighbour use-after-freecurated

Impact

The driver stored neighbour pointers without holding a reference, taking one only when the neighbour was used by a nexthop - a slab use-after-free when updating neighbour entries. Reproduced on an NVIDIA SN5600. Neighbour churn on a busy leaf is normal operation, so this is a switch crash that arrives on its own schedule and takes a rack's uplinks with it.

Who can reach it

Local on the switch, driven by neighbour table churn - which an attacker on an attached network can amplify by cycling ARP/ND entries.

What to do

Upgrade the switch OS to a build carrying kernel 6.19 or a stable backport (5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.64, 6.18.3). Switch OS upgrade and reload - fabric rolling window, one switch at a time with ECMP draining.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.