In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: fix BQL reset on SQ re-activation
mlx5e_queue_start() deactivates and re-activates all channels but closes only the queue being restarted. mlx5e_activate_txqsq() then unconditionally calls netdev_tx_reset_queue(), zeroing the BQL counters of channels that kept their in-flight TX WQEs. The next completion then over-charges and trips the BUG_ON() in dql_completed():
kernel BUG at lib/dynamic_queue_limits.c:99! RIP: 0010:dql_completed+0x23d/0x280 Call Trace: <IRQ> mlx5e_poll_tx_cq+0x668/0xa60 mlx5e_napi_poll+0x5b/0x7b0 net_rx_action+0x15a/0x580
Reset BQL only when the SQ has no bytes in flight (sq->cc == sq->pc).
In the case that reset is skipped, the outstanding WQEs will eventually complete and rebalance the dql. The dql->limit is carried across the reset.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade bpftool6.18Upgrade perf6.18-debuginfoUpgrade bpftool6.18-debuginfoUpgrade kernel6.18-debuginfo-common-aarch64Upgrade kernel-livepatch-6.18.48-107.148Upgrade kernel6.18-toolsUpgrade kernel6.18-tools-debuginfoUpgrade kernel6.18-modules-extraUpgrade kernel6.18-headersUpgrade kernel6.18Upgrade kernel6.18-tools-develUpgrade microvm-kernel6.18Upgrade kernel6.18-debuginfoUpgrade python3-perf6.18-debuginfoUpgrade perf6.18Upgrade kernel6.18-debuginfo-common-x86_64Upgrade python3-perf6.18Upgrade kernel6.18-modules-extra-commonUpgrade kernel6.18-devel | Sep 30, 2026 | Aug 22, 2026 |
| Redhat_linux | — | No solution exists | Aug 26, 2026 | Aug 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub