Database/Kernel, userspace & hypervisor
Linux kernel mlx5_ib (shared receive queue): The max_sge attribute for a shared receive queue is taken from the user
CVE-2024-40990Kernel, userspace & hypervisorRDMA/mlx5 add check for srq max_sge attributecurated
Impact
The max_sge attribute for a shared receive queue is taken from the user and used unchecked. A tenant process creating an SRQ supplies a value the kernel trusts - memory corruption from an ordinary verbs call available to any RDMA workload on the node.
Who can reach it
Local, low-privileged process with RDMA verbs access on an mlx5 device.
What to do
Upgrade the host kernel to 6.10 or a stable backport (5.10.221, 5.15.162, 6.1.96, 6.6.36, 6.9.7). Rolling reboot of the RDMA fleet.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.