Database/Kernel, userspace & hypervisor
Linux kernel mlx5_ib (shared receive queue): The max_sge attribute for a shared receive queue is taken from the user
CVSS 7.8CVE-2024-40990Kernel, userspace & hypervisorRDMA/mlx5 add check for srq max_sge attributecurated
Impact
The max_sge attribute for a shared receive queue is taken from the user and used unchecked. A tenant process creating an SRQ supplies a value the kernel trusts - memory corruption from an ordinary verbs call available to any RDMA workload on the node.
Who can reach it
Local, low-privileged process with RDMA verbs access on an mlx5 device.
What to do
Upgrade the host kernel to 6.10 or a stable backport (5.10.221, 5.15.162, 6.1.96, 6.6.36, 6.9.7). Rolling reboot of the RDMA fleet.
References
Related entries
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2024-41011 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel BPF: use-after-free freeing map elements that hold BPF timersCVE-2024-41045 · Linux kernel BPF timers (bpf_timer_cancel_and_free, hrtimer freed while still enqueued)High
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isCVE-2024-41092 · Linux i915 GPU kernel driverHigh
- Linux kernel (drivers/pci/msi): When MSI vector allocation for a PCI device fails, the core MSI code keeps using aCVE-2024-41096 · Linux kernel (drivers/pci/msi)High
- Linux kernel (drivers/gpu/drm/xe): The Xe VRAM manager computed a buffer object's minimum page size by shifting aCVE-2024-42066 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/i915/gem): The size of a partial GEM mapping is computed without accounting for theCVE-2024-42259 · Linux kernel (drivers/gpu/drm/i915/gem)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.