NVIDIA/Mellanox ConnectX driver (mlx5_ib completion-queue resize, init_cq_frag_buf): CQ resize initialised the wrong
Impact
CQ resize initialised the wrong buffer. Because get_cqe() always returns entries from the current cq->buf, enlarging a completion queue made the driver write initialisation patterns past the end of the smaller live buffer instead of into the new one - an out-of-bounds write whose length the tenant controls by choosing the resize delta, ending in a kernel panic in the reported case.
Who can reach it
Local, unprivileged. A tenant calls resize_cq with a larger size on an mlx5 device.
What to do
Kernel update making init_cq_frag_buf() address the buffer actually being initialised. No configuration workaround - CQ resize is part of the standard verbs API.
References
Related entries
- Linux kernel amdgpu kernel driver core (drm/amdgpu): A race condition or locking defect in the amdgpu kernel driverCVE-2021-47421 · Linux kernel amdgpu kernel driver core (drm/amdgpu)High
- Linux kernel amdgpu display core (DC/DM) (drm/amdgpu): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2021-47489 · Linux kernel amdgpu display core (DC/DM) (drm/amdgpu)High
- NVIDIA CUDA Toolkit - cuobjdump: An integer overflow reached by disassembling a corrupted fatbin gives remote codeCVE-2022-21821 · NVIDIA CUDA Toolkit - cuobjdumpHigh
- NVIDIA GPU Display Driver - Windows kernel mode layer (nvlddmkm.sys): Missing data validation lets a basic user causeCVE-2022-31606 · NVIDIA GPU Display Driver - Windows kernel mode layer (nvlddmkm.sys)High
- NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko): Missing input validation in nvidia.ko lets a basic localCVE-2022-31607 · NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko)High
- NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko): An optional D-Bus configuration file shippedCVE-2022-31608 · NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.