In the Linux kernel, the following vulnerability has been resolved:
mlxsw: spectrum_acl_tcam: Fix stack corruption
When tc filters are first added to a net device, the corresponding local
port gets bound to an ACL group in the device. The group contains a list
of ACLs. In turn, each ACL points to a different TCAM region where the
filters are stored. During forwarding, the ACLs are sequentially
evaluated until a match is found.
One reason to place filters in different regions is when they are added
with decreasing priorities and in an alternating order so that two
consecutive filters can never fit in the same region because of their
key usage.
In Spectrum-2 and newer ASICs the firmware started to report that the
maximum number of ACLs in a group is more than 16, but the layout of the
register that configures ACL groups (PAGT) was not updated to account
for that. It is therefore possible to hit stack corruption [1] in the
rare case where more than 16 ACLs in a group are required.
Fix by limiting the maximum ACL group size to the minimum between what
the firmware reports and the maximum ACLs that fit in the PAGT register.
Add a test case to make sure the machine does not crash when this
condition is hit.
[1]
Kernel panic - not syncing: stack-protector: Kernel stack is corrupted in: mlxsw_sp_acl_tcam_group_update+0x116/0x120
[...]
dump_stack_lvl+0x36/0x50
panic+0x305/0x330
__stack_chk_fail+0x15/0x20
mlxsw_sp_acl_tcam_group_update+0x116/0x120
mlxsw_sp_acl_tcam_group_region_attach+0x69/0x110
mlxsw_sp_acl_tcam_vchunk_get+0x492/0xa20
mlxsw_sp_acl_tcam_ventry_add+0x25/0xe0
mlxsw_sp_acl_rule_add+0x47/0x240
mlxsw_sp_flower_replace+0x1a9/0x1d0
tc_setup_cb_add+0xdc/0x1c0
fl_hw_replace_filter+0x146/0x1f0
fl_change+0xc17/0x1360
tc_new_tfilter+0x472/0xb90
rtnetlink_rcv_msg+0x313/0x3b0
netlink_rcv_skb+0x58/0x100
netlink_unicast+0x244/0x390
netlink_sendmsg+0x1e4/0x440
____sys_sendmsg+0x164/0x260
___sys_sendmsg+0x9a/0xe0
__sys_sendmsg+0x7a/0xc0
do_syscall_64+0x40/0xe0
entry_SYSCALL_64_after_hwframe+0x63/0x6b
Security readout for executives and security teams
Plain-English summary
This is a Linux kernel bug in the mlxsw networking driver that can corrupt the kernel stack and crash the machine. It affects a specialized scenario: systems using Spectrum-2 or newer switch ASICs with traffic-control ACL offload configurations requiring more than 16 ACLs in a group.
Executive priority
Prioritize for network appliances, switches, or Linux hosts using Mellanox/NVIDIA Spectrum hardware with tc offload. For typical servers, urgency is lower. Treat as an availability risk until patched.
Technical view
The mlxsw spectrum_acl_tcam code trusted firmware-reported ACL group limits larger than the PAGT register layout could support. When complex tc filter ordering required more than 16 ACLs in one group, mlxsw_sp_acl_tcam_group_update could overwrite stack data, triggering stack-protector panic. The fix caps group size to the register-supported maximum.
Likely exposure
Exposure is likely limited to Linux systems using the mlxsw driver with Spectrum-2 or newer ASICs and complex tc filter/ACL offload rules. General Linux servers without this hardware or driver path are unlikely to be affected.
Exploitation context
No active exploitation is indicated by the provided sources, and the CVE is not in KEV. The described trigger is a rare configuration path involving tc filters and ACL group expansion, not a remote unauthenticated attack path in the sources.
Researcher notes
The public record documents a resolved Linux kernel stack corruption bug with an observed panic trace. Sources do not establish privilege requirements, exploitability beyond crash, or remote reachability. Avoid assuming affected scope beyond mlxsw Spectrum ACL TCAM handling.
Mitigation direction
Apply Linux stable or distribution kernel updates containing the referenced mlxsw fix.
Review Debian LTS guidance if running affected Debian LTS kernels.
If patching is delayed, reduce reliance on complex mlxsw tc ACL offload configurations.
Check vendor kernel guidance for exact affected and fixed package versions.
Validation and detection
Inventory systems using the mlxsw driver and Spectrum-2 or newer ASICs.
Confirm running kernels include the referenced stable fix for CVE-2024-26586.
Review tc filter policies for complex ACL group usage on mlxsw-backed interfaces.
Monitor kernel logs for mlxsw ACL TCAM stack-protector panic signatures.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-26586 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.