Database/Firmware, BMC & network fabric
Linux kernel iWARP driver drivers/infiniband/hw/cxgb3/iwch_cm.c (Chelsio T3): Unauthenticated remote code execution in
Impact
Unauthenticated remote code execution in the kernel, reachable from the fabric. The iWARP connection-manager path mis-identifies an error condition and frees a buffer it then keeps using; a crafted packet to the listening RDMA endpoint drives the use-after-free to arbitrary kernel code execution. RDMA connection managers listen before any application-level authentication exists - there is no credential to present - so anything that can put packets on the storage/compute fabric owns the kernel. In a cluster where tenant traffic and RDMA control traffic share the same L2 domain, one compromised tenant VM reaches every node running this HCA.
Who can reach it
Network, pre-auth. Any host able to send packets to the node's iWARP/RDMA-CM listener - which on a flat cluster fabric includes every other tenant. No credentials, no prior foothold on the target.
What to do
Kernel upgrade to 4.5+ or a vendor backport of commit 67f1aee6f45059fd6b0f5b0ecb2c97ad0451f6b3 (iw_cxgb3: fix incorrectly returning error on success). Rolling reboot required. Compensating control while you schedule it: put the RDMA fabric on its own isolated L2/VLAN with no tenant-reachable path, and firewall the iWARP listener - RDMA-CM has no authentication of its own, so network segmentation is the only pre-patch boundary. The iw_cxgb3 driver was removed from mainline entirely in later kernels; if you still have Chelsio T3 parts racked, that hardware is past end of support and should be scheduled out.
References
Related entries
- Cisco NX-OS / FXOS (Cisco Fabric Services): Unauthenticated remote code execution as root through Cisco FabricCVE-2018-0314 · Cisco NX-OS / FXOS (Cisco Fabric Services)Critical
- Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameter: Local file inclusion through directoryCVE-2018-12031 · Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameterCritical
- Dell iDRAC7/8: CGI injection giving unauthenticated remote code execution as root on the BMCCVE-2018-1207 · Dell iDRAC7/8Critical
- Intel Baseboard Management Controller firmware before 1.43.91f76955 (Intel server boards and systems): An unprivilegedCVE-2018-12171 · Intel Baseboard Management Controller firmware before 1.43.91f76955 (Intel server boards and systems)Critical
- QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 switch modules for IBM BladeCenter: Three undocumentedCVE-2018-18202 · QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 switch modules for IBM BladeCenterCritical
- Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): The card's integrated web serverCVE-2018-7243 · Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.