Database/Firmware, BMC & network fabric
Linux kernel InfiniBand connection manager drivers/infiniband/core/cma.c and cm.c - cm_work_handler race: A race in the
Impact
A race in the InfiniBand connection-manager work handler. Sending a CM request while other request handlers are still running drives an invalid pointer dereference and panics the node - no account on the target, no authentication step, just frames on the fabric. The fix is two commits, and the second one takes a reference on the cm_id before invoking the callback, which means the underlying defect is a live object being used without a reference held. That is use-after-free shaped, so treating the impact ceiling as 'panic' is the optimistic reading. Either way it is one tenant crashing other tenants' nodes across a shared IB fabric.
Who can reach it
Adjacent network, pre-auth. Any host that can send InfiniBand CM requests to the target - i.e. any node or tenant on the same fabric partition.
What to do
Kernel upgrade or vendor backport of both commits 25ae21a10112875763c18b385624df713a288a05 (RDMA/cma: fix crash in request handlers) and 29963437a48475036353b95ab142bf199adb909e (IB/cm: bump reference count on cm_id before invoking callback) - applying only the first leaves the refcount defect in place. Rolling reboot. The structural control, shared with every other pre-auth RDMA-CM issue in this set, is fabric partitioning: IB P_Keys or RoCE VLAN separation so tenants cannot address each other's connection managers at all, because the CM itself has no authentication to enable.
References
Related entries
- ibacm 1.0.7 (InfiniBand Communication Manager Assistant daemon) - world-writable log and ibacm.port files: The RDMACVE-2012-4518 · ibacm 1.0.7 (InfiniBand Communication Manager Assistant daemon) - world-writable log and ibacm.port filesMedium
- Linux kernel RDMA connection manager drivers/infiniband/core/cma.c - cma_req_handler (RoCE): Pre-authentication remoteCVE-2014-2739 · Linux kernel RDMA connection manager drivers/infiniband/core/cma.c - cma_req_handler (RoCE)Medium
- Cisco Nexus 9000 ACI Mode Switch Software (fabric infrastructure VLAN): The earlier instance of the same ACI class ofCVE-2019-1890 · Cisco Nexus 9000 ACI Mode Switch Software (fabric infrastructure VLAN)Medium
- Intel E810 Ethernet Controller firmware: Buffer overflow in early E810 firmware, triggerable by an unauthenticatedCVE-2020-24501 · Intel E810 Ethernet Controller firmwareMedium
- Intel processors (shared resource isolation): Improper isolation of shared processor resources allowing informationCVE-2020-24511 · Intel processors (shared resource isolation)Medium
- Intel Atom processors (domain-bypass transient execution): A domain-bypass transient execution flaw on Atom partsCVE-2020-24513 · Intel Atom processors (domain-bypass transient execution)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.