Database/Firmware, BMC & network fabric
Linux kernel Soft-RoCE completer (rdma_rxe, invalid lkey handling in atomic operations): The local key is the RDMA
Impact
The local key is the RDMA access-control token - it is what stops one queue pair touching another's registered memory. Soft-RoCE failed to record the WQE status when a LOCAL_WRITE failed, so an atomic operation submitted with a deliberately wrong lkey walked into a WARN and kernel panic instead of returning a completion error. The reachability is the point: supplying a bad lkey is the most basic thing an attacker probing RDMA isolation does, and on this driver it crashed the node rather than being rejected cleanly.
Who can reach it
Local, unprivileged - a tenant posts an atomic work request with an invalid lkey on a Soft-RoCE device.
What to do
Kernel update returning a CQE error instead of falling through. Blacklist rdma_rxe on nodes with hardware RDMA that do not need software RoCE.
References
Related entries
- Linux kernel RDMA core + mlx5_ib (ib_uverbs_ex_create_flow, flow steering rule creation): The port number a tenantCVE-2021-47265 · Linux kernel RDMA core + mlx5_ib (ib_uverbs_ex_create_flow, flow steering rule creation)Medium
- Intel processors (branch history injection): BHI / Spectre-BHB: even with eIBRS enabled, the branch history buffer isCVE-2022-0001 · Intel processors (branch history injection)Medium
- Intel processors (intra-mode branch target injection): The intra-mode sibling of BHI: branch predictor state is sharedCVE-2022-0002 · Intel processors (intra-mode branch target injection)Medium
- AMD processors - branch predictor aliasing causing wrong branch type prediction (AMD-SB-1037): Aliases in the branchCVE-2022-23816 · AMD processors - branch predictor aliasing causing wrong branch type prediction (AMD-SB-1037)Medium
- fwupd's Redfish plugin: Any unprivileged local user on the host can read a working BMC credential out of a config fileCVE-2022-3287 · fwupd's Redfish pluginMedium
- AMD processors - power reporting side channel against SEV VMs: An authenticated attacker uses the platform's powerCVE-2023-20575 · AMD processors - power reporting side channel against SEV VMsMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.