Database/Firmware, BMC & network fabric
Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cq: Integer overflow on the
Impact
Integer overflow on the completion-queue poll path. A tenant passes an oversized entry count through the uverbs POLL_CQ command, the size computation wraps, and the kernel corrupts memory past the allocation - a heap-corruption primitive available to anyone holding the uverbs device node, with privilege escalation not excluded. Historically important because it is the first of the uverbs command-argument overflows and it establishes the pattern that CVE-2014-8159 and CVE-2016-8636 repeat: the verbs uAPI trusted tenant-supplied sizes.
Who can reach it
Local, unprivileged - read/write on /dev/infiniband/uverbsN, i.e. any RDMA-enabled tenant container.
What to do
Kernel upgrade past 2.6.37 or a vendor backport; rolling reboot. Any fleet still exposed to this is running a kernel a decade and a half old, so the operator decision is really a platform upgrade, not a patch. Interim control is the same as for the other uverbs bugs: stop mapping /dev/infiniband/uverbs* into untrusted workloads.
References
Related entries
- Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cq: Kernel memory disclosureCVE-2011-1044 · Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cqMedium
- Linux kernel InfiniBand/RDMA uAPI write() handlers (ib_uverbs, rdma_ucm, ib_ucm, ib_umad): The whole drivers/infinibandCVE-2016-4565 · Linux kernel InfiniBand/RDMA uAPI write() handlers (ib_uverbs, rdma_ucm, ib_ucm, ib_umad)High
- Linux kernel Soft-RoCE drivers/infiniband/sw/rxe/rxe_mr.c (mem_check_range): The bounds check that is supposed toCVE-2016-8636 · Linux kernel Soft-RoCE drivers/infiniband/sw/rxe/rxe_mr.c (mem_check_range)High
- Intel Server Platform Services (SPS) firmware 4.0 kernelCVE-2017-5709 · Intel Server Platform Services (SPS) firmware 4.0 kernel - the server-chipset variant of ME, Lewisburg PCH / Xeon…High
- Intel processors supporting SGX (memory protection): Insufficient memory protection on SGX-capable processors givesCVE-2019-0123 · Intel processors supporting SGX (memory protection)High
- Intel processor graphics blitter command streamer: The graphics blitter accepted commands that could reference memoryCVE-2019-0155 · Intel processor graphics blitter command streamerHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.