Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/core): An unprivileged tenant corrupts RDMA connection-manager state and lands a
Impact
An unprivileged tenant corrupts RDMA connection-manager state and lands a use-after-free. An address-resolve call that should have been rejected outright still overwrites the source address of a listening connection id, which later makes cancellation walk a list it does not own - freed memory is read and linked into live kernel lists.
Who can reach it
Any process with /dev/infiniband/rdma_cm (ucma) inside a tenant container: put an id into LISTEN, then issue a resolve on the same id, then destroy it. Plain write() calls on the device, no capabilities and no cooperating peer required. Provider-independent, so soft-RoCE nodes are exposed too.
What to do
No fixed release is published in this record - apply the listed stable fix commits or run a current stable kernel. Interim: drop /dev/infiniband/rdma_cm from tenant containers that do not need connection-manager access.
References
Related entries
- Linux kernel (drivers/infiniband/core): A 32-bit advance counter in the core RDMA block iterator wraps when a singleCVE-2023-53026 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/infiniband/core): When the IOMMU coalesces a large memory registration into one block spanningCVE-2026-53133 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/infiniband/core): Because re-registration can swap the protection domain behind a memory regionCVE-2026-74334 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/infiniband/core): A peer that drives enough connection churn across a node's IB port pushes theCVE-2024-50095 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/infiniband/core): Rdma_join_multicast accepted queue-pair types other than UD and built theCVE-2023-53525 · Linux kernel (drivers/infiniband/core)Medium
- Linux kernel (drivers/infiniband/core): Bursts of network neighbour updates crash the node. Each event re-initializes aCVE-2025-37772 · Linux kernel (drivers/infiniband/core)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.