Database/Firmware, BMC & network fabric
Linux kernel mlx4_ib (legacy ConnectX-3 RDMA): Same class of bug on the older mlx4 stack: the user-supplied
Impact
Same class of bug on the older mlx4 stack: the user-supplied log_sq_bb_count shift wraps in set_user_sq_size(). Any tenant with RDMA access on a ConnectX-3-era host gets a user-controlled shift into kernel sizing logic. Matters for operators still running legacy mlx4 nodes alongside a modern fleet.
Who can reach it
Local, low-privileged process creating an RDMA queue pair on an mlx4 device.
What to do
Upgrade the host kernel to 6.4 or a stable backport (4.19.283, 5.4.243, 5.10.180, 5.15.111, 6.1.28, 6.2.15, 6.3.2). Host reboot. Strategically, this is a prompt to retire remaining ConnectX-3/mlx4 hardware rather than keep patching it.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Adding a TC flower rule while the device is in NIC mode makesCVE-2023-54216 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel mlxsw (Spectrum switch ASIC ACL TCAM): On Spectrum-2 and newer, firmware reports more than 16 ACLs perCVE-2024-26586 · Linux kernel mlxsw (Spectrum switch ASIC ACL TCAM)High
- Linux kernel (drivers/infiniband/hw/hfi1): An off-by-one in the SDMA descriptor accounting lets the descriptor array inCVE-2024-26766 · Linux kernel (drivers/infiniband/hw/hfi1)High
- AMI AptioV UEFI BIOS (SmmComputrace DXE module): The SmmComputrace DXE module leaks stack and global memory to a localCVE-2024-33656 · AMI AptioV UEFI BIOS (SmmComputrace DXE module)High
- AMI AptioV UEFI BIOS (SMM modules): An SMM vulnerability letting a privileged local attacker execute arbitrary codeCVE-2024-33657 · AMI AptioV UEFI BIOS (SMM modules)High
- AMI AptioV BIOS (memory buffer restriction failure): Local privilege escalation and potentially arbitrary codeCVE-2024-33658 · AMI AptioV BIOS (memory buffer restriction failure)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.