ThreatCluster

Microsoft Fixes CVEs for mlx5 Driver Issues in Cybersecurity Update

First seen 18 Feb 2026, 12:23 UTC Api.Msrc.Microsoft 50

Article Content

Browse articles
ThreatCluster

Microsoft has addressed two vulnerabilities in the mlx5 driver related to network and RDMA functionalities. CVE-2025-38109 concerns the unloading of ECVF vports during shutdown, while CVE-2025-38161 addresses error handling upon firmware failures during RQ destruction. Both vulnerabilities were published on July 3, 2025.

Timeline

2025-07-03
CVE-2025-38109 published
2025-07-03
CVE-2025-38161 published
2026-02-18
Fix for CVE-2025-38109 announced
2026-02-18
Fix for CVE-2025-38161 announced