Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/hw/hfi1): The driver drops the last reference on a process's memory-descriptor
Impact
The driver drops the last reference on a process's memory-descriptor structure and then keeps using it while unpinning pages. A newly started process can be handed that same structure, so one tenant's cleanup corrupts another running task's address-space state - the reported symptoms include a mangled mmap lock leading to a system-wide hang.
Who can reach it
A tenant with the hfi1 character device in its container, doing pinned-memory RDMA (typical MPI workload), that exits or aborts abruptly while page unpinning is still in flight - an MPI_Abort is the documented trigger, so the tenant controls the timing. Requires hfi1 hardware (Intel Omni-Path).
What to do
Update to 5.10 or later per the record, or apply the listed stable commits on your branch. Interim: keep the hfi1 device node out of untrusted containers; there is no runtime toggle that closes the race.
References
Related entries
- Linux kernel (drivers/infiniband/hw/hfi1): User SDMA requests with multiple payload buffers are read past the declaredCVE-2023-52474 · Linux kernel (drivers/infiniband/hw/hfi1)High
- Linux kernel (drivers/infiniband/hw/hfi1): An off-by-one in the SDMA descriptor accounting lets the descriptor array inCVE-2024-26766 · Linux kernel (drivers/infiniband/hw/hfi1)High
- Linux kernel (drivers/infiniband/hw/hfi1): The node panics when the fabric link goes down while any sender is waitingCVE-2022-49931 · Linux kernel (drivers/infiniband/hw/hfi1)High
- Linux kernel (drivers/infiniband/hw/irdma): Use-after-free on completion-queue teardown. The driver frees the CQCVE-2022-50137 · Linux kernel (drivers/infiniband/hw/irdma)High
- Linux kernel (drivers/infiniband/sw/rxe): A tenant gets a double free in the kernel heap through a failed memoryCVE-2022-50543 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): The async firmware-command context can be freed while aCVE-2022-50726 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.