Database/Firmware, BMC & network fabric
Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ): After the switch to shared
Impact
After the switch to shared completion queues the cq_context no longer identifies the queue, but the SEND error handler still used it - so a transport-level error such as retry-counter-exceeded dereferences a stale pointer and crashes the target. The trigger is link disruption on the RDMA fabric, which a co-tenant can induce (link flap, congestion, or simply disconnecting mid-transfer) without any access to the target itself.
Who can reach it
Remote/fabric. Any condition that produces a SEND completion error on the target's RDMA queue pairs - reachable by a peer able to disturb the fabric path.
What to do
Kernel update obtaining the queue from wc->qp instead of cq_context. Fabric-level: keep storage RDMA traffic on its own partition/VLAN so tenant-induced congestion does not reach the target's queue pairs.
References
Related entries
- AMD SEV-SNP - VM_HSAVE_PA MSR validation: Insufficient validation of the VM_HSAVE_PA model-specific register lets aCVE-2022-23818 · AMD SEV-SNP - VM_HSAVE_PA MSR validationHigh
- OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end): bmcweb is the single process behind Redfish, the webCVE-2022-2809 · OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end)High
- AMI MegaRAC: User enumeration — lets an attacker map valid BMC accounts before credential attackCVE-2022-2827 · AMI MegaRACHigh
- Insyde InsydeH2O (UsbCoreDxe USB working buffer, DMA TOCTOU): UsbCoreDxe builds its USB transaction working bufferCVE-2022-30283 · Insyde InsydeH2O (UsbCoreDxe USB working buffer, DMA TOCTOU)High
- OpenBMC bmcweb multipart_parser (second variant found during the CVE-2022-2809 fix): The second bug the fuzzer foundCVE-2022-3409 · OpenBMC bmcweb multipart_parser (second variant found during the CVE-2022-2809 fix)High
- Dell Enterprise SONiC OS (SSH cryptographic key): A cryptographic key weakness in SONiC's SSH implementation letsCVE-2022-34425 · Dell Enterprise SONiC OS (SSH cryptographic key)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.