Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/sw/siw): A tenant gets an out-of-bounds kernel array read using values it controls.
Impact
A tenant gets an out-of-bounds kernel array read using values it controls. The driver translates completion opcode and status fields through fixed lookup tables without validating them, and those fields sit in a completion queue that is mapped into the tenant's own address space - so the tenant writes the index the kernel then trusts. Usable for kernel memory disclosure or to crash the node.
Who can reach it
Tenant container holding /dev/infiniband/uverbs* on a node with the soft-iWARP driver (siw) loaded. Two ways in: write garbage opcode/status into the mmap'd CQ entries, or push the QP into ERROR state and post work so the flush path builds a completion with an undefined opcode. A fabric peer can force the ERROR state by dropping the connection, so the second path is partly remote-driven.
What to do
No fixed release is published in this record - apply the listed stable fix commits or run a current stable kernel. Interim: unload/blacklist siw where soft-iWARP is not required, and do not expose /dev/infiniband/* to containers that only need ordinary TCP networking.
References
Related entries
- Linux kernel (drivers/infiniband/sw/siw): A remote peer turns a connection drop into a kernel use-after-free. TheCVE-2022-50666 · Linux kernel (drivers/infiniband/sw/siw)Critical
- Linux kernel (drivers/infiniband/sw/siw): Soft-iWARP memory-region allocation stores the memory object into the MR andCVE-2021-47012 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/siw): Soft-iWARP published a new queue pair into the lookup table before itsCVE-2026-68417 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/siw): A remote peer crashes the node during connection setup. When the MPACVE-2022-50136 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/siw): When soft-iWARP fails to process an inbound MPA connection requestCVE-2023-52513 · Linux kernel (drivers/infiniband/sw/siw)High
- AMD Secure Processor - hardware config integrity across power save/restore: Hardware configuration state is notCVE-2023-31316 · AMD Secure Processor - hardware config integrity across power save/restoreHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.