Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/ulp/srp): The SRP abort handler completes the SCSI command itself, after which the
Impact
The SRP abort handler completes the SCSI command itself, after which the SCSI error handler re-queues or re-finishes the same command - a use-after-free of the command structure. This fires on any aborted SRP command, so a storage timeout caused by fabric congestion (including congestion a noisy tenant creates) corrupts kernel memory on the node that mounts the SRP storage.
Who can reach it
Triggered on the initiator side by any SCSI abort, which means an ordinary command timeout - not only a hostile target. In a shared cluster a tenant that saturates the RDMA fabric can induce those timeouts on nodes using SRP-over-IB storage. Conditional on the ib_srp module being loaded and SRP targets being mounted.
What to do
Update to a stable kernel carrying the srp_abort fix (commits 26788a5b48d9 / b9bdffb3f9aa); the record lists the affected series as 3.1 through 3.7 baselines, so verify your distro backport. Interim: move affected nodes off SRP-over-IB storage, or drain them if SRP timeouts are already being observed.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/xsk): An RX buffer on the legacy receive queue is releasedCVE-2023-54223 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/xsk)Critical
- Supermicro BMC firmware web/management service (X11/X12/X13/H12/H13/B12/B13, CMM6): An attacker who never authenticatesCVE-2024-36435 · Supermicro BMC firmware web/management service (X11/X12/X13/H12/H13/B12/B13, CMM6)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server builds an RDMA work request around a scatter-gather listCVE-2024-36476 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel Soft-RoCE completer (rdma_rxe, rxe_comp_queue_pkt): An inbound response packet is queued to the completerCVE-2024-38544 · Linux kernel Soft-RoCE completer (rdma_rxe, rxe_comp_queue_pkt)Critical
- OpenBMC slpd-lite (Service Location Protocol daemon, UDP 427): slpd-lite is a small SLP responder that OpenBMC installsCVE-2024-41660 · OpenBMC slpd-lite (Service Location Protocol daemon, UDP 427)Critical
- Linux kernel (drivers/infiniband/core): Tearing down an iWARP connection frees the rdma_id_private whileCVE-2024-42285 · Linux kernel (drivers/infiniband/core)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.