Database/Firmware, BMC & network fabric
Linux kernel RDMA connection manager drivers/infiniband/core/cma.c - cma_req_handler (RoCE): Pre-authentication remote
Impact
Pre-authentication remote crash of any node running an RDMA-CM listener. Crafted RoCE connection-request traffic drives cma_req_handler down an address-resolution path owned by a different module, the pointer is wrong, and the kernel panics. The isolation lesson matters more than the crash: the RDMA connection manager accepts and parses attacker-controlled connection requests before any authentication exists, so on a shared fabric every node's kernel is parsing untrusted input from every tenant by design. One tenant reboots a rack's worth of training nodes and takes out everyone's in-flight jobs and their unsaved optimizer state.
Who can reach it
Adjacent network, pre-auth. Any host on the RoCE/IB fabric that can reach the node's RDMA-CM listener. No credentials and no account on the target.
What to do
Kernel upgrade past 3.14.1 or a vendor backport; rolling reboot. The structural fix that outlives this one CVE is fabric segmentation - keep the RDMA control plane on a dedicated, tenant-unreachable L2 domain, and where the fabric must be shared, use partition keys (IB P_Keys) or RoCE VLAN isolation so tenants cannot address each other's CM listeners at all. RDMA-CM itself has no authentication to turn on.
References
Related entries
- Cisco Nexus 9000 ACI Mode Switch Software (fabric infrastructure VLAN): The earlier instance of the same ACI class ofCVE-2019-1890 · Cisco Nexus 9000 ACI Mode Switch Software (fabric infrastructure VLAN)Medium
- Intel E810 Ethernet Controller firmware: Buffer overflow in early E810 firmware, triggerable by an unauthenticatedCVE-2020-24501 · Intel E810 Ethernet Controller firmwareMedium
- Intel processors (shared resource isolation): Improper isolation of shared processor resources allowing informationCVE-2020-24511 · Intel processors (shared resource isolation)Medium
- Intel Atom processors (domain-bypass transient execution): A domain-bypass transient execution flaw on Atom partsCVE-2020-24513 · Intel Atom processors (domain-bypass transient execution)Medium
- Intel SGX DCAP (datacenter attestation primitives): An improper conditions check in DCAP lets an unauthenticatedCVE-2020-8766 · Intel SGX DCAP (datacenter attestation primitives)Medium
- Intel Ethernet 800 Series Controller firmware: Out-of-bounds read in 800-series (E810 family) adapter firmwareCVE-2021-0009 · Intel Ethernet 800 Series Controller firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.