Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/hw/hns): The completion-queue refcount is not held under a lock, so a CQ asynchronous
Impact
The completion-queue refcount is not held under a lock, so a CQ asynchronous event that lands while the same CQ is being destroyed dereferences freed memory. A tenant that can provoke a CQ error event while tearing the CQ down gets a use-after-free in kernel slab memory shared with the rest of the node.
Who can reach it
Local: a tenant holding /dev/infiniband/uverbs* on a HiSilicon hns_roce adapter creates a CQ, provokes an asynchronous CQ event (for example a CQ overrun), and destroys the CQ concurrently. No fabric peer or root needed. Conditional on hns_roce hardware being the RDMA path on that node.
What to do
No fixed version is recorded in this entry; boot a stable kernel carrying the xa_lock refcount fix (commits 330c825e66ef / 763780ef0336). Interim: drop /dev/infiniband device nodes from tenant containers on hns_roce nodes.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): A command that waits on the busy command-queue semaphore startsCVE-2024-38556 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- ASPEED USB device controller driver (drivers/usb/gadget/udc/aspeed_udc.c): The BMC presents itself to the host over USBCVE-2024-46836 · ASPEED USB device controller driver (drivers/usb/gadget/udc/aspeed_udc.c)High
- Dell SmartFabric OS10 (execution with unnecessary privileges): Low-privileged local attacker reaches command executionCVE-2024-48837 · Dell SmartFabric OS10 (execution with unnecessary privileges)High
- Dell SmartFabric OS10 (command injection): Command injection from a low-privileged local account leading to codeCVE-2024-49557 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (improper privilege management): A low-privileged local attacker elevates privileges on the switchCVE-2024-49558 · Dell SmartFabric OS10 (improper privilege management)High
- Dell SmartFabric OS10 (command injection): A low-privileged local attacker executes commands on the switch OSCVE-2024-49560 · Dell SmartFabric OS10 (command injection)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.