Database/Firmware, BMC & network fabric
Linux kernel RDMA core netlink (nldev_stat_set_counter_dynamic_doit): The dynamic-counter netlink setter bounded its
Impact
The dynamic-counter netlink setter bounded its index from above but not from below, so a negative index underflowed past the start of the counter array. It is reachable from the RDMA netlink admin surface, which in clusters that hand namespaced RDMA administration to tenant operators (or to a fabric-management sidecar) is not as far from the tenant as it looks.
Who can reach it
Local RDMA netlink message; requires the privilege to configure RDMA statistics counters in the namespace.
What to do
Kernel update changing the index to an unsigned type. Audit which workloads hold CAP_NET_ADMIN in their netns - on many clusters that capability is granted far more broadly than intended, and it is the gate on this and a family of similar nldev bugs.
References
Related entries
- AMD SEV-SNP firmware, guest teardown / UMC key seed handling: TENANT HANDOFF FAILURECVE-2023-31355 · AMD SEV-SNP firmware, guest teardown / UMC key seed handlingMedium
- AMI MegaRAC SPx (IPMI handler): Arbitrary file upload and download through the BMC's IPMI handlerCVE-2023-34342 · AMI MegaRAC SPx (IPMI handler)Medium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2023-47855 · Intel TDX moduleMedium
- Cisco NX-OS CLI: Command injection giving root on the switch's underlying OS from an admin CLI sessionCVE-2024-20399 · Cisco NX-OS CLIMedium
- Intel TDX SEAM loader (Seamldr): Sensitive information is not cleared before a resource is reused in the SEAM loaderCVE-2024-21850 · Intel TDX SEAM loader (Seamldr)Medium
- AMD SEV-SNP firmware - input validation: Improper input validation in SEV-SNP lets a malicious hypervisor read orCVE-2024-21978 · AMD SEV-SNP firmware - input validationMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.