Database/Firmware, BMC & network fabric
Linux kernel NVMe-oF RDMA target (nvmet, uninitialised completion-entry result field): This is a straight kernel-stack
Impact
This is a straight kernel-stack disclosure to a remote party. The first two dwords of every NVMe completion entry were left uninitialised on the RDMA transport when the command did not define them - TCP and FC zeroed them, RDMA did not - so the target returned leftover kernel stack contents to whichever initiator issued the command. A remote tenant with an NVMe-oF connection harvests kernel stack bytes at whatever rate it can submit commands, which is exactly the primitive you need to defeat KASLR before using one of the corruption bugs above.
Who can reach it
Remote. Any initiator connected over NVMe-oF/RDMA; the leak arrives in the ordinary completion path, no malformed input required.
What to do
Kernel update explicitly initialising cqe.result on the RDMA path. Nothing configurable helps - the leak is in normal, well-formed traffic, which also means it produces no anomalous-traffic signal to detect on.
References
Related entries
- Linux kernel InfiniBand core (ib_umad): ib_umad kept received management datagrams on an unbounded listCVE-2024-42145 · Linux kernel InfiniBand core (ib_umad)High
- AMI AptioV BIOS (TOCTOU race condition): Firmware TOCTOU race allowing execution of arbitrary code on the target deviceCVE-2024-42444 · AMI AptioV BIOS (TOCTOU race condition)High
- AMI AptioV BIOS (TOCTOU race condition): Second firmware TOCTOU race reaching arbitrary code execution with scope changeCVE-2024-42446 · AMI AptioV BIOS (TOCTOU race condition)High
- GRUB2 (gettext / message catalogue): Integer overflow reading a crafted translation catalogue gives bothCVE-2024-45776 · GRUB2 (gettext / message catalogue)High
- GRUB2 (gettext / message catalogue): Second integer overflow in the same translation path, producing a heapCVE-2024-45777 · GRUB2 (gettext / message catalogue)High
- GRUB2 (HFS filesystem parser): An unbounded strcpy of the HFS volume name overflows a fixed bufferCVE-2024-45782 · GRUB2 (HFS filesystem parser)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.