Linux Kernel BlueField Device ECVF VPorts Unload Use-After-Free Vulnerability

Vulnerability

A use-after-free vulnerability has been addressed in the Linux kernel's handling of virtual function ports on BlueField devices. This issue arose because the ingress ACL table for the virtual ports was not properly destroyed during the shutdown process, leading to a use-after-free condition. The vulnerability is related to the ECVF functionality, which operates independently of the ECPF vport existence capability.

Impact

Exploitation of this vulnerability could lead to a use-after-free condition, allowing for potential memory corruption or arbitrary code execution.

Added: Jul 3, 2025, 11:21 AM
Updated: Jul 3, 2025, 11:21 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
7.7
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.