Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/ulp/ipoib): A PKEY child interface created over netlink comes up with multiple TX/RX
Impact
A PKEY child interface created over netlink comes up with multiple TX/RX queues even when the parent device supports only one, and the first packet sent on it dereferences a NULL pointer and panics the node. PKEY partitions are exactly how an InfiniBand fabric separates tenants, so the isolation mechanism itself becomes the crash trigger.
Who can reach it
Two-stage: the partition child interface is created by the operator or orchestration over netlink (needs CAP_NET_ADMIN), after which any unprivileged workload sending traffic on that interface panics the node. Conditional on legacy IPoIB with PKEY child interfaces on a device that supports a single queue.
What to do
Update to 5.4.232 / 5.10.168 / 5.15.94 / 6.1.12 or later. Interim: create PKEY child interfaces through the legacy sysfs path rather than netlink, or avoid PKEY child interfaces on single-queue IPoIB devices until patched.
References
Related entries
- Linux kernel (drivers/infiniband/ulp/ipoib): The IPoIB multicast join task drops its lock mid-iteration, letting aCVE-2023-52587 · Linux kernel (drivers/infiniband/ulp/ipoib)Medium
- ASPEED video engine capture driver (drivers/media/platform/aspeed) - iKVM path: The video engine writes pastCVE-2023-52916 · ASPEED video engine capture driver (drivers/media/platform/aspeed) - iKVM pathHigh
- Linux kernel (drivers/infiniband/core): A 32-bit advance counter in the core RDMA block iterator wraps when a singleCVE-2023-53026 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): A userspace DEVX consumer can issue a firmware command opcodeCVE-2023-53340 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When a regular receive queue is reactivated after an AF_XDPCVE-2023-53394 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/infiniband/hw/bnxt_re): The driver keeps scheduling completion handlers for a queue pair afterCVE-2023-54048 · Linux kernel (drivers/infiniband/hw/bnxt_re)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.