Database/Firmware, BMC & network fabric
Intel irdma driver (Ethernet Controller RDMA for Linux): Improper access control in the Intel RDMA driver lets an
Impact
Improper access control in the Intel RDMA driver lets an unauthenticated user escalate privilege. RDMA is the transport for collective operations across an AI cluster, and the driver maps queue pairs directly into user processes - so an access-control failure here is one workload reaching another's RDMA resources on the same host.
Who can reach it
Unauthenticated, which on an RDMA fabric means anything that can present traffic to the verbs interface. Treat the RDMA fabric as an authentication boundary that is not actually authenticating.
What to do
Update the Intel irdma driver to 1.9.30 or later. Module reload drops RDMA connections and kills in-flight collectives - drain the node. No firmware component for this one.
References
Related entries
- Intel TDX module: An out-of-bounds read in the TDX module reachable by an authenticated user, leaking informationCVE-2024-33607 · Intel TDX moduleMedium
- Intel Atom processors (shared predictor transient execution): Shared microarchitectural predictor state influencesCVE-2024-43420 · Intel Atom processors (shared predictor transient execution)Medium
- Intel processors (indirect branch predictor race): Branch Privilege Injection: a race in how the indirect branchCVE-2024-45332 · Intel processors (indirect branch predictor race)Medium
- Intel Core processors, 10th generation (shared predictor state): Shared predictor state influencing transient executionCVE-2025-20623 · Intel Core processors, 10th generation (shared predictor state)Medium
- Intel Core Ultra processors (branch prediction unit initialisation): Part of the Training Solo family: incorrectCVE-2025-24495 · Intel Core Ultra processors (branch prediction unit initialisation)Medium
- Arista EOS: stale 802.1X ACL entry survives re-auth and is applied to a new supplicantCVE-2026-75944 · Arista EOS AclAgent (802.1X supplicant ACL state)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.