Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server builds an RDMA work request around a scatter-gather list
Impact
The RTRS server builds an RDMA work request around a scatter-gather list whose storage has already gone out of scope, so the transport copies data through a dangling descriptor. Upstream saw it as a kernel NULL-pointer fault inside the memory-copy path on the server - a remote client can crash the storage-serving node, and the underlying stale descriptor is a corruption primitive, not just a panic.
Who can reach it
Server-side and driven by the fabric: a client that establishes an RTRS/RNBD session and issues I/O drives the affected path on the target node, before any application-level trust decision. Conditional on the rtrs-srv module being loaded and exporting block devices (RNBD storage backend); the reported trace runs over soft-RoCE (rdma_rxe), which makes it reachable without special hardware.
What to do
No fixed version is recorded in this entry; boot a stable kernel carrying the ib_sge scope fix (commits 7eaa71f56a6f / 143378075904). Interim: stop exporting RNBD/RTRS targets from shared nodes, or restrict which fabric addresses may open RTRS sessions.
References
Related entries
- Linux kernel (drivers/infiniband/ulp/rtrs): A remote client corrupts kernel linked lists on the RDMA block-storageCVE-2025-21805 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): On the RTRS server, a failure while publishing a new session's sysfsCVE-2026-64033 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server trusts a connecting client to send its session-info messageCVE-2024-50062 · Linux kernel (drivers/infiniband/ulp/rtrs)High
- Linux kernel Soft-RoCE completer (rdma_rxe, rxe_comp_queue_pkt): An inbound response packet is queued to the completerCVE-2024-38544 · Linux kernel Soft-RoCE completer (rdma_rxe, rxe_comp_queue_pkt)Critical
- OpenBMC slpd-lite (Service Location Protocol daemon, UDP 427): slpd-lite is a small SLP responder that OpenBMC installsCVE-2024-41660 · OpenBMC slpd-lite (Service Location Protocol daemon, UDP 427)Critical
- Linux kernel (drivers/infiniband/core): Tearing down an iWARP connection frees the rdma_id_private whileCVE-2024-42285 · Linux kernel (drivers/infiniband/core)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.