LiveActive security incident?Get immediate response
CVE Record

CVE-2024-43880: mlxsw: spectrum_acl_erp: Fix object nesting warning

In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_erp: Fix object nesting warning ACLs in Spectrum-2 and newer ASICs can reside in the algorithmic TCAM (A-TCAM) or in the ordinary circuit TCAM (C-TCAM). The former can contain more ACLs (i.e., tc filters), but the number of masks in each region (i.e., tc chain) is limited. In order to mitigate the effects of the above limitation, the device allows filters to share a single mask if their masks only differ in up to 8 consecutive bits. For example, dst_ip/25 can be represented using dst_ip/24 with a delta of 1 bit. The C-TCAM does not have a limit on the number of masks being used (and therefore does not support mask aggregation), but can contain a limited number of filters. The driver uses the "objagg" library to perform the mask aggregation by passing it objects that consist of the filter's mask and whether the filter is to be inserted into the A-TCAM or the C-TCAM since filters in different TCAMs cannot share a mask. The set of created objects is dependent on the insertion order of the filters and is not necessarily optimal. Therefore, the driver will periodically ask the library to compute a more optimal set ("hints") by looking at all the existing objects. When the library asks the driver whether two objects can be aggregated the driver only compares the provided masks and ignores the A-TCAM / C-TCAM indication. This is the right thing to do since the goal is to move as many filters as possible to the A-TCAM. The driver also forbids two identical masks from being aggregated since this can only happen if one was intentionally put in the C-TCAM to avoid a conflict in the A-TCAM. The above can result in the following set of hints: H1: {mask X, A-TCAM} -> H2: {mask Y, A-TCAM} // X is Y + delta H3: {mask Y, C-TCAM} -> H4: {mask Z, A-TCAM} // Y is Z + delta After getting the hints from the library the driver will start migrating filters from one region to another while consulting the computed hints and instructing the device to perform a lookup in both regions during the transition. Assuming a filter with mask X is being migrated into the A-TCAM in the new region, the hints lookup will return H1. Since H2 is the parent of H1, the library will try to find the object associated with it and create it if necessary in which case another hints lookup (recursive) will be performed. This hints lookup for {mask Y, A-TCAM} will either return H2 or H3 since the driver passes the library an object comparison function that ignores the A-TCAM / C-TCAM indication. This can eventually lead to nested objects which are not supported by the library [1]. Fix by removing the object comparison function from both the driver and the library as the driver was the only user. That way the lookup will only return exact matches. I do not have a reliable reproducer that can reproduce the issue in a timely manner, but before the fix the issue would reproduce in several minutes and with the fix it does not reproduce in over an hour. Note that the current usefulness of the hints is limited because they include the C-TCAM indication and represent aggregation that cannot actually happen. This will be addressed in net-next. [1] WARNING: CPU: 0 PID: 153 at lib/objagg.c:170 objagg_obj_parent_assign+0xb5/0xd0 Modules linked in: CPU: 0 PID: 153 Comm: kworker/0:18 Not tainted 6.9.0-rc6-custom-g70fbc2c1c38b #42 Hardware name: Mellanox Technologies Ltd. MSN3700C/VMOD0008, BIOS 5.11 10/10/2018 Workqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work RIP: 0010:objagg_obj_parent_assign+0xb5/0xd0 [...] Call Trace: <TASK> __objagg_obj_get+0x2bb/0x580 objagg_obj_get+0xe/0x80 mlxsw_sp_acl_erp_mask_get+0xb5/0xf0 mlxsw_sp_acl_atcam_entry_add+0xe8/0x3c0 mlxsw_sp_acl_tcam_entry_create+0x5e/0xa0 mlxsw_sp_acl_tcam_vchunk_migrate_one+0x16b/0x270 mlxsw_sp_acl_tcam_vregion_rehash_work+0xbe/0x510 process_one_work+0x151/0x370

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2024-43880 is a Linux kernel driver issue in mlxsw ACL handling for Mellanox/NVIDIA Spectrum-2 and newer switch ASICs. Under specific ACL mask aggregation conditions, the driver can create unsupported nested objects and trigger a kernel warning. Business exposure appears narrow, but the real impact is not fully described in the sources.

Executive priority

Treat this as targeted infrastructure hygiene, not a broad emergency. Prioritize kernel updates for Linux-based switching platforms or appliances using Spectrum ASICs. Severity and impact are not quantified in the supplied sources, so exposure validation matters before escalating business risk.

Technical view

The mlxsw spectrum_acl_erp logic used objagg hint lookups that ignored A-TCAM versus C-TCAM placement. During ACL region migration, recursive hint lookup could match the wrong object and create unsupported nested parent relationships in objagg. The fix removes the comparison function so lookups require exact object matches.

Likely exposure

Most relevant to Linux systems acting as switches or network appliances using the mlxsw driver with Spectrum-2 or newer ASICs and tc ACL filters. General Linux servers without this hardware and driver path are unlikely to be exposed based on the provided sources.

Exploitation context

The bundle does not show KEV listing, public exploitation, exploit code, or a reliable reproducer. The upstream text says reproduction was unreliable but occurred within minutes before the fix in the author's test environment.

Researcher notes

Key evidence is the upstream kernel description and stable fix references. The issue is logic-specific to mlxsw ACL ERP mask aggregation and objagg hint lookup behavior. Sources do not provide CVSS, CWE, confirmed crash impact, privilege requirements, or active exploitation evidence.

Mitigation direction

  • Update to a vendor Linux kernel containing the referenced stable fixes.
  • Apply Debian LTS kernel updates where the cited Debian advisories apply.
  • For custom kernels, review and backport the matching stable commit for the maintained branch.
  • Prioritize affected network appliances over general-purpose Linux hosts.
  • Monitor vendor advisories for any clarified impact or operational workaround.

Validation and detection

  • Inventory Linux systems using mlxsw with Spectrum-2 or newer ASICs.
  • Confirm whether tc ACL filters are deployed on those systems.
  • Compare running kernel versions against vendor fixed releases or referenced stable commits.
  • Review kernel logs for objagg or mlxsw ACL rehash warnings.
  • Document non-exposure for systems without the mlxsw hardware path.
Prepared
Confidence
medium
Sources
11

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-43880 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
10Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux9069a3817d82b01b3a55da382c774e3575946130, 9069a3817d82b01b3a55da382c774e3575946130, 9069a3817d82b01b3a55da382c774e3575946130, 9069a3817d82b01b3a55da382c774e3575946130, 9069a3817d82b01b3a55da382c774e3575946130, 9069a3817d82b01b3a55da382c774e3575946130, 9069a3817d82b01b3a55da382c774e3575946130unaffected
LinuxLinux5.1, 0, 5.4.282, 5.10.224, 5.15.165, 6.1.103, 6.6.44, 6.10.3, 6.11affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.