Database/Firmware, BMC & network fabric
Linux kernel RDMA core + mlx5_ib (ib_uverbs_ex_create_flow, flow steering rule creation): The port number a tenant
Impact
The port number a tenant supplies when creating an RDMA flow steering rule was never validated against the device's real port count before being handed to the driver. Flow steering is the mechanism that decides which packets land in which tenant's queue pair, so an unvalidated port index in the rule-creation path is both a kernel crash primitive (the mlx5_ib oops in the report) and a reason to distrust the boundary that is supposed to keep one tenant's traffic out of another's receive queues.
Who can reach it
Local ioctl on /dev/infiniband/uverbs* by any process allowed to create flow rules - which is any RDMA-capable tenant container. Unprivileged.
What to do
Kernel update moving port validation into the core create_flow handler. No configuration workaround; RDMA flow steering cannot be selectively disabled without breaking RoCE traffic classification.
References
Related entries
- Intel processors (branch history injection): BHI / Spectre-BHB: even with eIBRS enabled, the branch history buffer isCVE-2022-0001 · Intel processors (branch history injection)Medium
- Intel processors (intra-mode branch target injection): The intra-mode sibling of BHI: branch predictor state is sharedCVE-2022-0002 · Intel processors (intra-mode branch target injection)Medium
- AMD processors - branch predictor aliasing causing wrong branch type prediction (AMD-SB-1037): Aliases in the branchCVE-2022-23816 · AMD processors - branch predictor aliasing causing wrong branch type prediction (AMD-SB-1037)Medium
- fwupd's Redfish plugin: Any unprivileged local user on the host can read a working BMC credential out of a config fileCVE-2022-3287 · fwupd's Redfish pluginMedium
- AMD processors - power reporting side channel against SEV VMs: An authenticated attacker uses the platform's powerCVE-2023-20575 · AMD processors - power reporting side channel against SEV VMsMedium
- Intel Ethernet Controller E810 Series firmware: A race condition in E810 firmware lets an authenticated local userCVE-2023-22276 · Intel Ethernet Controller E810 Series firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.