Database/Firmware, BMC & network fabric
Linux kernel RDS RDMA path net/rds/rdma.c - rds_rdma_pages: The page-count arithmetic for an RDS RDMA scatter-gather
Impact
The page-count arithmetic for an RDS RDMA scatter-gather request overflows on a crafted iovec, so the kernel allocates a short buffer and then fills it as if it were large - a heap overflow reachable by an unprivileged local user, with code execution not excluded. This is the RDMA-specific sibling of the RDS root bug above and lives in exactly the code path an operator would be exercising if they did adopt RDS over InfiniBand for a low-latency service.
Who can reach it
Local, unprivileged - an RDS socket plus a crafted iovec. Same autoload consideration as CVE-2010-3904.
What to do
Kernel upgrade or vendor backport; rolling reboot across the fleet. As with CVE-2010-3904, blacklisting the rds module is the immediate, no-downtime control and is the right default on any node that does not deliberately run RDS - which is nearly all of them.
References
Related entries
- Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cq: Integer overflow on theCVE-2010-4649 · Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cqHigh
- Linux kernel InfiniBand/RDMA uAPI write() handlers (ib_uverbs, rdma_ucm, ib_ucm, ib_umad): The whole drivers/infinibandCVE-2016-4565 · Linux kernel InfiniBand/RDMA uAPI write() handlers (ib_uverbs, rdma_ucm, ib_ucm, ib_umad)High
- Linux kernel Soft-RoCE drivers/infiniband/sw/rxe/rxe_mr.c (mem_check_range): The bounds check that is supposed toCVE-2016-8636 · Linux kernel Soft-RoCE drivers/infiniband/sw/rxe/rxe_mr.c (mem_check_range)High
- Intel Server Platform Services (SPS) firmware 4.0 kernelCVE-2017-5709 · Intel Server Platform Services (SPS) firmware 4.0 kernel - the server-chipset variant of ME, Lewisburg PCH / Xeon…High
- Intel processors supporting SGX (memory protection): Insufficient memory protection on SGX-capable processors givesCVE-2019-0123 · Intel processors supporting SGX (memory protection)High
- Intel processor graphics blitter command streamer: The graphics blitter accepted commands that could reference memoryCVE-2019-0155 · Intel processor graphics blitter command streamerHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.