Database/Firmware, BMC & network fabric
Linux bnxt_re RoCE driver (bnxt_re_create_srq memory leak): A tenant can exhaust host memory by repeatedly triggering
Impact
A tenant can exhaust host memory by repeatedly triggering shared-receive-queue creation failures through the RDMA verbs interface. This is a straightforward noisy-neighbour denial of service available to any container or VM granted RDMA access, and it needs no privilege beyond opening verbs.
Who can reach it
Any local process with access to the RDMA verbs device — in practice, any tenant container given RDMA.
What to do
Kernel upgrade plus host reboot. Independently: apply memory cgroup limits to RDMA-capable workloads and restrict verbs device access to workloads that actually need it — both container-runtime config changes, and both good practice regardless of this CVE.
References
Related entries
- Intel processors (vector register sampling): Stale values left in vector registers can be sampled by other contextsCVE-2020-0548 · Intel processors (vector register sampling)Medium
- Intel processors (L1D eviction sampling) / SGX attestation keys: Stale data can be sampled out of L1D fill buffersCVE-2020-0549 · Intel processors (L1D eviction sampling) / SGX attestation keysMedium
- AMD EPYC SEV-ES / SEV-SNP - information disclosure: An information-disclosure flaw in SEV-ES and SEV-SNP on EPYC lets aCVE-2020-12966 · AMD EPYC SEV-ES / SEV-SNP - information disclosureMedium
- Intel processors (fast store forwarding predictor): Improper isolation of a shared microarchitectural resource letsCVE-2020-8698 · Intel processors (fast store forwarding predictor)Medium
- Intel processors (fast store forwarding predictor initialisation): Improper initialisation of a shared predictorCVE-2021-0145 · Intel processors (fast store forwarding predictor initialisation)Medium
- AMD SEV firmware - ASK validation in SEND_START: Insufficient validation of the AMD SEV Signing Key in the SEND_STARTCVE-2021-26320 · AMD SEV firmware - ASK validation in SEND_STARTMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.