Database/Firmware, BMC & network fabric
Linux kernel InfiniBand qib driver (user SDMA path, qib_user_sdma_pkt): The user SDMA descriptor path did arithmetic on
Impact
The user SDMA descriptor path did arithmetic on user-supplied buffer sizes without overflow checks, so a tenant could overflow addrlimit or bytes_togo and drive a kernel heap buffer overflow directly from the send path. The qib user SDMA interface is a zero-copy DMA submission channel - the whole point is that userspace hands the adapter descriptors - which makes an integer overflow here a straight route to controlled kernel memory corruption on a shared node.
Who can reach it
Local, unprivileged, via the qib character device on nodes carrying QLogic/Intel TrueScale InfiniBand HCAs. Still relevant because older IB fabrics get recycled into cheap secondary GPU clusters long after the frontier fleet has moved to ConnectX.
What to do
Kernel update adding the overflow checks across the user-controlled arithmetic. If the fleet has no qib hardware, blacklist the ib_qib module - that is a cheap, reboot-free way to remove the surface entirely, and worth doing on any node where the driver is present but the hardware is not.
References
Related entries
- Linux kernel (drivers/infiniband/hw/irdma): In the physical-buffer-list allocator, a chunk is freed while still linkedCVE-2021-47614 · Linux kernel (drivers/infiniband/hw/irdma)High
- Linux kernel (drivers/infiniband/sw/rxe): The soft-RoCE queue-pair init error path frees the send-queue ring and leavesCVE-2021-47616 · Linux kernel (drivers/infiniband/sw/rxe)High
- Insyde InsydeH2O (StorageSecurityCommandDxe SMI input buffer, DMA TOCTOU): Highest-scored DMA entry in the 2022 batchCVE-2022-34325 · Insyde InsydeH2O (StorageSecurityCommandDxe SMI input buffer, DMA TOCTOU)High
- EDK II SecurityPkg (Tcg2Dxe, Tcg2MeasureGptTable): A crafted GPT partition table overflows the heap inside the veryCVE-2022-36763 · EDK II SecurityPkg (Tcg2Dxe, Tcg2MeasureGptTable)High
- EDK II MdePkg (CreateHob, HOB list construction): An integer overflow in the routine that allocates Hand-Off BlocksCVE-2022-36765 · EDK II MdePkg (CreateHob, HOB list construction)High
- APC Easy UPS Online Monitoring Software - embedded database credentials: Hardcoded credentials let any local userCVE-2022-42973 · APC Easy UPS Online Monitoring Software - embedded database credentialsHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.