Database/Firmware, BMC & network fabric
Linux kernel SRP target (ib_srpt, LIO port lifetime vs RDMA port lifetime): The SRP target's port structures were owned
Impact
The SRP target's port structures were owned by the RDMA core while the LIO target port data inside them was owned by the SCSI target subsystem, and the two lifetimes were not decoupled - KASAN caught a use-after-free in srpt_enable_tpg. This is on the target side of SCSI-over-RDMA, the process exporting block devices to the cluster, so a use-after-free during target reconfiguration lands in the daemon that mediates every initiator's access to those devices.
Who can reach it
Local on the storage target, racing RDMA port teardown against LIO target-portal-group configuration. Requires the ability to drive target configuration or to time an RDMA port event against it.
What to do
Kernel update decoupling srpt_port and srpt_port_id lifetimes. Operationally: do not reconfigure LIO target portal groups while RDMA ports are being brought up or down - sequence storage-target maintenance rather than overlapping it.
References
Related entries
- Linux kernel SEV-ES #VC handler - MMIO access checking: Incorrect access checking in the SEV-ES #VC handler andCVE-2023-46813 · Linux kernel SEV-ES #VC handler - MMIO access checkingHigh
- Dell iDRAC Service Module (incorrect default permissions): Weak default folder permissions let an unprivileged localCVE-2024-22428 · Dell iDRAC Service Module (incorrect default permissions)High
- Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620CVE-2024-47975 · Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620…High
- Intel Xeon 6 with TDX: overlapping protected memory ranges in SMM allow privilege escalationCVE-2025-31936 · Intel Xeon 6 processors with Intel TDX (protected memory range overlap handling in SMM)High
- EDK II (SMM environment, Machine Check Exception handling): Machine Check Exceptions are enabled before SMM installsCVE-2025-3770 · EDK II (SMM environment, Machine Check Exception handling)High
- Lenovo XClarity Orchestrator: microservices accept invalid TLS certificates, exposing management trafficCVE-2026-16792 · Lenovo XClarity Orchestrator 2.2.0 (microservice TLS certificate validation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.