Database/Firmware, BMC & network fabric
Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cq: Kernel memory disclosure
Impact
Kernel memory disclosure straight into a tenant's address space. The POLL_CQ response buffer is not zeroed before being copied out, so when fewer completions are returned than the buffer holds, the remaining bytes are whatever was previously in that kernel allocation - other tenants' RDMA metadata, pointers useful for defeating KASLR, and residual heap contents. A tenant can poll in a loop and harvest a continuous stream of kernel memory with no crash, no log entry, and no anomalous behaviour to detect. Low severity on paper, high value in practice as the reconnaissance step that makes the heap-corruption bugs on this same device node reliable.
Who can reach it
Local, unprivileged - /dev/infiniband/uverbsN access. Fully silent; nothing in the host's telemetry distinguishes it from normal verbs traffic.
What to do
Kernel upgrade past 2.6.37 or a vendor backport that memsets the response structure; rolling reboot. There is no runtime mitigation short of revoking uverbs access, because the leak happens in the normal, expected code path rather than an error path - you cannot rate-limit or alert your way out of it.
References
Related entries
- Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cq: Integer overflow on theCVE-2010-4649 · Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cqHigh
- Linux kernel SRP target drivers/infiniband/ulp/srpt/ib_srpt.c: An SRP initiator that issues an ABORT_TASK against anCVE-2016-6327 · Linux kernel SRP target drivers/infiniband/ulp/srpt/ib_srpt.cMedium
- AMD Ryzen with AGESA microcode - FMA3 instruction sequence hang: A long series of FMA3 instructions hangs the systemCVE-2017-7262 · AMD Ryzen with AGESA microcode - FMA3 instruction sequence hangMedium
- Intel processors (speculative store bypass): Spectre v4: a load speculatively executes before an older storeCVE-2018-3639 · Intel processors (speculative store bypass)Medium
- Intel SGX Platform Software for Linux (AESM daemon): A local attacker can disable the AESM daemonCVE-2018-3689 · Intel SGX Platform Software for Linux (AESM daemon)Medium
- Intel SGX driver for Linux: Insufficient input validation in the out-of-tree SGX Linux driver lets a localCVE-2019-0157 · Intel SGX driver for LinuxMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.