Database/Firmware, BMC & network fabric
Linux kernel Soft-RoCE completer (rdma_rxe, rxe_comp_queue_pkt): An inbound response packet is queued to the completer
Impact
An inbound response packet is queued to the completer before the code dereferences the same skb to bump a counter. If the completer task is already running on another CPU it can free the skb first, so the counter update reads freed memory. The trigger is a remote packet arriving at the right moment, which means an attacker who can send RoCE traffic at a node - a co-tenant on the same L2 fabric, since RoCEv2 is just UDP/4791 - can drive a kernel use-after-free with no credential. The kernel CNA rates it network, unauthenticated, full CIA.
Who can reach it
Remote and unauthenticated. Any host that can put RoCEv2 packets onto the node's fabric interface, including a container on another node in the same tenant network if RoCE is not segmented.
What to do
Kernel update reordering the counter access ahead of the enqueue. Practical short-term control: unload rdma_rxe on nodes that have real RDMA NICs and do not need software RoCE, and enforce a fabric ACL so UDP/4791 is only accepted from the cluster's own RDMA subnet rather than from any tenant-routable network.
References
Related entries
- OpenBMC slpd-lite (Service Location Protocol daemon, UDP 427): slpd-lite is a small SLP responder that OpenBMC installsCVE-2024-41660 · OpenBMC slpd-lite (Service Location Protocol daemon, UDP 427)Critical
- Linux kernel (drivers/infiniband/core): Tearing down an iWARP connection frees the rdma_id_private whileCVE-2024-42285 · Linux kernel (drivers/infiniband/core)Critical
- Rittal IoT Interface and CMC III Processing Unit - firmware upgrade signature check: The admin web interface verifiesCVE-2024-47943 · Rittal IoT Interface and CMC III Processing Unit - firmware upgrade signature checkCritical
- AMI MegaRAC SPx (Redfish Host Interface): Unauthenticated auth bypass, full BMC takeover, malicious firmware flash.CVE-2024-54085 · AMI MegaRAC SPx (Redfish Host Interface)Critical
- Linux bnxt_en driver (5760X / P7 aggregation ID mask): The bnxt_en driver mishandles the aggregation ID mask on 5760XCVE-2024-56656 · Linux bnxt_en driver (5760X / P7 aggregation ID mask)Critical
- Linux kernel (drivers/infiniband/hw/bnxt_re): The driver advertises support for 13 scatter-gather entries per workCVE-2024-57936 · Linux kernel (drivers/infiniband/hw/bnxt_re)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.