Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/ulp/ipoib): The IPoIB multicast join task drops its lock mid-iteration, letting a
Impact
The IPoIB multicast join task drops its lock mid-iteration, letting a concurrent device flush move entries off the list it is walking. The loop then spins forever and the node hard-locks - observed in production on RHEL kernels. One fabric event during multicast activity takes the entire shared node offline, killing every tenant's workload on it.
Who can reach it
Driven by fabric and link events, not by a tenant device node: an IB port event, subnet-manager sweep, or link flap runs ipoib_ib_dev_flush_light concurrently with a multicast join. Any node running IPoIB with multicast groups is exposed; a tenant generating multicast join churn on the IPoIB interface widens the window. Conditional on the ib_ipoib module being in use.
What to do
No fixed version is recorded in this entry; boot a stable kernel carrying the mcast list locking fix (commits 4c8922ae8eb8 / 615e3adc2042). Interim: reduce IPoIB multicast usage on shared nodes and stabilise the fabric (avoid unnecessary port flaps / SM re-sweeps) until patched.
References
Related entries
- Linux kernel (drivers/infiniband/ulp/ipoib): A PKEY child interface created over netlink comes up with multiple TX/RXCVE-2023-52745 · Linux kernel (drivers/infiniband/ulp/ipoib)High
- Linux kernel (drivers/infiniband/core): Rdma_join_multicast accepted queue-pair types other than UD and built theCVE-2023-53525 · Linux kernel (drivers/infiniband/core)Medium
- Arista EOS (L2 forwarding / VLAN isolation): Ingress traffic on a layer-2 port is forwarded out ports belonging to aCVE-2024-11185 · Arista EOS (L2 forwarding / VLAN isolation)Medium
- Redfish API implementation on Cisco UCS B-Series, UCS Managed C-Series and UCS X-Series servers: An administrator-levelCVE-2024-20365 · Redfish API implementation on Cisco UCS B-Series, UCS Managed C-Series and UCS X-Series serversMedium
- Intel Ethernet Controller E810 firmware: An unauthenticated attacker on the network can take an E810 NIC out of serviceCVE-2024-24983 · Intel Ethernet Controller E810 firmwareMedium
- SEV-ES / SEV-SNP guest kernel - unsolicited #VC (vector 29) injection: An untrusted hypervisor can inject the #VCCVE-2024-25742 · SEV-ES / SEV-SNP guest kernel - unsolicited #VC (vector 29) injectionMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.