ThreatCluster

Memory Leak and Use-After Fixes in mlxsw Spectrum ACL TCAM

First seen 18 Feb 2026, 10:13 UTC Api.Msrc.Microsoft 41

Article Content

Browse articles
ThreatCluster

Two vulnerabilities, CVE-2024-35853 and CVE-2024-35854, were addressed in the mlxsw spectrum_acl_tcam component. CVE-2024-35853 involves a memory leak during rehashing, while CVE-2024-35854 addresses a potential use-after-free issue. Both vulnerabilities were published on May 17, 2024, affecting systems utilizing this component.

Timeline

2024-05-17
CVE-2024-35853 published
2024-05-17
CVE-2024-35854 published
2026-02-18
Information published regarding fixes