LiveActive security incident?Get immediate response
CVE Record

CVE-2024-26586: mlxsw: spectrum_acl_tcam: Fix stack corruption

In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix stack corruption When tc filters are first added to a net device, the corresponding local port gets bound to an ACL group in the device. The group contains a list of ACLs. In turn, each ACL points to a different TCAM region where the filters are stored. During forwarding, the ACLs are sequentially evaluated until a match is found. One reason to place filters in different regions is when they are added with decreasing priorities and in an alternating order so that two consecutive filters can never fit in the same region because of their key usage. In Spectrum-2 and newer ASICs the firmware started to report that the maximum number of ACLs in a group is more than 16, but the layout of the register that configures ACL groups (PAGT) was not updated to account for that. It is therefore possible to hit stack corruption [1] in the rare case where more than 16 ACLs in a group are required. Fix by limiting the maximum ACL group size to the minimum between what the firmware reports and the maximum ACLs that fit in the PAGT register. Add a test case to make sure the machine does not crash when this condition is hit. [1] Kernel panic - not syncing: stack-protector: Kernel stack is corrupted in: mlxsw_sp_acl_tcam_group_update+0x116/0x120 [...] dump_stack_lvl+0x36/0x50 panic+0x305/0x330 __stack_chk_fail+0x15/0x20 mlxsw_sp_acl_tcam_group_update+0x116/0x120 mlxsw_sp_acl_tcam_group_region_attach+0x69/0x110 mlxsw_sp_acl_tcam_vchunk_get+0x492/0xa20 mlxsw_sp_acl_tcam_ventry_add+0x25/0xe0 mlxsw_sp_acl_rule_add+0x47/0x240 mlxsw_sp_flower_replace+0x1a9/0x1d0 tc_setup_cb_add+0xdc/0x1c0 fl_hw_replace_filter+0x146/0x1f0 fl_change+0xc17/0x1360 tc_new_tfilter+0x472/0xb90 rtnetlink_rcv_msg+0x313/0x3b0 netlink_rcv_skb+0x58/0x100 netlink_unicast+0x244/0x390 netlink_sendmsg+0x1e4/0x440 ____sys_sendmsg+0x164/0x260 ___sys_sendmsg+0x9a/0xe0 __sys_sendmsg+0x7a/0xc0 do_syscall_64+0x40/0xe0 entry_SYSCALL_64_after_hwframe+0x63/0x6b

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This is a Linux kernel bug in the mlxsw networking driver that can corrupt the kernel stack and crash the machine. It affects a specialized scenario: systems using Spectrum-2 or newer switch ASICs with traffic-control ACL offload configurations requiring more than 16 ACLs in a group.

Executive priority

Prioritize for network appliances, switches, or Linux hosts using Mellanox/NVIDIA Spectrum hardware with tc offload. For typical servers, urgency is lower. Treat as an availability risk until patched.

Technical view

The mlxsw spectrum_acl_tcam code trusted firmware-reported ACL group limits larger than the PAGT register layout could support. When complex tc filter ordering required more than 16 ACLs in one group, mlxsw_sp_acl_tcam_group_update could overwrite stack data, triggering stack-protector panic. The fix caps group size to the register-supported maximum.

Likely exposure

Exposure is likely limited to Linux systems using the mlxsw driver with Spectrum-2 or newer ASICs and complex tc filter/ACL offload rules. General Linux servers without this hardware or driver path are unlikely to be affected.

Exploitation context

No active exploitation is indicated by the provided sources, and the CVE is not in KEV. The described trigger is a rare configuration path involving tc filters and ACL group expansion, not a remote unauthenticated attack path in the sources.

Researcher notes

The public record documents a resolved Linux kernel stack corruption bug with an observed panic trace. Sources do not establish privilege requirements, exploitability beyond crash, or remote reachability. Avoid assuming affected scope beyond mlxsw Spectrum ACL TCAM handling.

Mitigation direction

  • Apply Linux stable or distribution kernel updates containing the referenced mlxsw fix.
  • Review Debian LTS guidance if running affected Debian LTS kernels.
  • If patching is delayed, reduce reliance on complex mlxsw tc ACL offload configurations.
  • Check vendor kernel guidance for exact affected and fixed package versions.

Validation and detection

  • Inventory systems using the mlxsw driver and Spectrum-2 or newer ASICs.
  • Confirm running kernels include the referenced stable fix for CVE-2024-26586.
  • Review tc filter policies for complex ACL group usage on mlxsw-backed interfaces.
  • Monitor kernel logs for mlxsw ACL TCAM stack-protector panic signatures.
Prepared
Confidence
high
Sources
9

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-26586 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
8Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxc3ab435466d5109b2c7525a3b90107d4d9e918fc, c3ab435466d5109b2c7525a3b90107d4d9e918fc, c3ab435466d5109b2c7525a3b90107d4d9e918fc, c3ab435466d5109b2c7525a3b90107d4d9e918fc, c3ab435466d5109b2c7525a3b90107d4d9e918fc, c3ab435466d5109b2c7525a3b90107d4d9e918fcunaffected
LinuxLinux4.19, 0, 5.10.209, 5.15.148, 6.1.79, 6.6.14, 6.7.2, 6.8affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.