Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/sw/siw): Soft-iWARP memory-region allocation stores the memory object into the MR and
Impact
Soft-iWARP memory-region allocation stores the memory object into the MR and then frees it if ID allocation fails, leaving the MR pointing at freed memory that the error path immediately dereferences. A use-after-free on the memory-registration path, reachable without any RDMA hardware.
Who can reach it
An unprivileged process on a node with siw loaded registers memory regions until the ID allocator fails - a container can drive that with its own resource limits. No HCA, no fabric peer, no host root.
What to do
No fixed version is listed in the record - take the stable kernel carrying 30b9e92d0b5e (or 608a4b90ece0 / 3e22b88e02c1) and reboot. Interim: unload and blacklist siw where soft-iWARP is not required.
References
Related entries
- Linux kernel (drivers/infiniband/sw/siw): Soft-iWARP published a new queue pair into the lookup table before itsCVE-2026-68417 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/siw): A remote peer crashes the node during connection setup. When the MPACVE-2022-50136 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/siw): When soft-iWARP fails to process an inbound MPA connection requestCVE-2023-52513 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/siw): A tenant gets an out-of-bounds kernel array read using values it controls.CVE-2022-50736 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/siw): A remote peer turns a connection drop into a kernel use-after-free. TheCVE-2022-50666 · Linux kernel (drivers/infiniband/sw/siw)Critical
- Linux kernel (drivers/infiniband/sw/rxe): When soft-RoCE queue-pair initialisation fails, the QP structure is left fullCVE-2021-47078 · Linux kernel (drivers/infiniband/sw/rxe)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.