Database/Kernel, userspace & hypervisor
Linux kernel SMC-D diagnostics (smc_diag, rmb_desc access during connection dump): Dumping SMC-D connections while
Impact
Dumping SMC-D connections while connections are churning dereferences a remote memory buffer descriptor that has already gone away, crashing the node. The reproducer is nothing exotic - run a web benchmark under smc_run and poll smcss -D in a loop. That means routine monitoring can kill a node, and it also means a tenant able to trigger the diag dump path can do so deliberately while generating connection churn.
Who can reach it
Local. Requires the ability to issue SMC diag netlink dumps while SMC connections are being torn down; monitoring agents do this on a timer.
What to do
Kernel update guarding the rmb_desc access. Until patched, stop polling SMC diagnostics on nodes carrying live SMC traffic - the monitoring is the trigger.
References
Related entries
- Linux kernel (netfilter): nft_chain_filter NETDEV_UNREGISTER mishandling for inet/ingress basechains - UAFCVE-2024-26808 · Linux kernel (netfilter)Medium
- Linux kernel (drivers/iommu/intel): The whole node hangs. VT-d keeps re-issuing an ATS device-TLB invalidation to aCVE-2024-26891 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/iommufd): The cache-invalidation ioctl calls a driver operation that may not exist, jumpingCVE-2024-46824 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (net/xfrm): An SA created with an AF_UNSPEC selector escaped prefix-length validation, and the kernel thenCVE-2024-50142 · Linux kernel (net/xfrm)Medium
- Linux kernel (drivers/iommu/intel): Attaching a nested parent domain skips allocating the invalidation batch structureCVE-2024-56668 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/pci/pcie): The ASPM link state of a PCIe switch is freed as soon as ANY function on the upstreamCVE-2024-58093 · Linux kernel (drivers/pci/pcie)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.