Database/Firmware, BMC & network fabric
Linux kernel (drivers/pci/switch): If a userspace process is holding the Switchtec management character device open
Impact
If a userspace process is holding the Switchtec management character device open when the switch is surprise-removed, the final release runs long after the driver is gone - the MMIO mapping is already torn down, so the release path's register write takes a fatal page fault, and the DMA teardown that follows hands a stale device pointer to dma_free_coherent(). A userspace file descriptor thereby outlives and then corrupts kernel state belonging to the PCIe switch that fans out the node's GPUs and NVMe.
Who can reach it
Needs the switchtec driver bound to a Microsemi/Microchip PCIe switch - real hardware in GPU and NVMe fabric chassis - plus a process holding /dev/switchtec* open, which is the management or telemetry agent that normally does. The trigger is device-side: a surprise removal, link drop or switch reset while that fd is open. Access to the chardev is root/administrative, so this is not a tenant-initiated exploit; it is a management-plane crash of a shared node that a misbehaving switch can provoke.
What to do
Boot a kernel that moves the MRPC DMA shutdown into switchtec_pci_remove() after stdev_kill() and takes a counted reference on the pdev. Interim: have management agents close /dev/switchtec* rather than holding it open indefinitely, and keep the chardev out of containers.
References
Related entries
- Avocent DSR2030 / SVIP1020 KVM-over-IP appliance: A reflected XSS in the appliance's web interface lets an attackerCVE-2024-34923 · Avocent DSR2030 / SVIP1020 KVM-over-IP applianceMedium
- Intel Xeon 6 E-core with TDX or SGX: Improper restriction of software interfaces to hardware features on Xeon 6 E-coreCVE-2024-48869 · Intel Xeon 6 E-core with TDX or SGXMedium
- Intel Ethernet E810 Series and Ethernet 700 Series firmware: Out-of-bounds write in firmware across both the E810 lineCVE-2022-36382 · Intel Ethernet E810 Series and Ethernet 700 Series firmwareMedium
- Intel processors with SGX (shared resource isolation): Improper isolation of shared microarchitectural resources lets aCVE-2022-38090 · Intel processors with SGX (shared resource isolation)Medium
- Linux kernel RDMA core netlink (nldev_stat_set_counter_dynamic_doit): The dynamic-counter netlink setter bounded itsCVE-2022-49199 · Linux kernel RDMA core netlink (nldev_stat_set_counter_dynamic_doit)Medium
- AMD SEV-SNP firmware, guest teardown / UMC key seed handling: TENANT HANDOFF FAILURECVE-2023-31355 · AMD SEV-SNP firmware, guest teardown / UMC key seed handlingMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.