Database/Firmware, BMC & network fabric
Linux bnxt_en driver (XDP_REDIRECT double DMA unmap): A double DMA unmap in the XDP_REDIRECT path
Impact
A double DMA unmap in the XDP_REDIRECT path. Double-unmapping a DMA region is a memory-corruption primitive that touches the IOMMU mapping state, which is precisely the mechanism that keeps a device from reaching memory it should not. Anywhere you run XDP-based load balancing or packet steering in front of inference serving — a common pattern — this is live code.
Who can reach it
Traffic through the driver's XDP_REDIRECT path on a host with an XDP program attached.
What to do
Kernel/driver upgrade plus host reboot. Interim: detach XDP programs from Broadcom NICs, which is a live change but costs you whatever the XDP program was doing.
References
Related entries
- Lantronix PremierWave 2050 console server (Web Manager): An attacker who can log into the web management console getsCVE-2021-21872 · Lantronix PremierWave 2050 console server (Web Manager)Critical
- Lantronix PremierWave 2050 console server (Web Manager): Same class of bug as the Traceroute injection on this deviceCVE-2021-21883 · Lantronix PremierWave 2050 console server (Web Manager)Critical
- Linux kernel iWARP driver drivers/infiniband/hw/cxgb3/iwch_cm.c (Chelsio T3): Unauthenticated remote code execution inCVE-2015-8812 · Linux kernel iWARP driver drivers/infiniband/hw/cxgb3/iwch_cm.c (Chelsio T3)Critical
- Cisco NX-OS / FXOS (Cisco Fabric Services): Unauthenticated remote code execution as root through Cisco FabricCVE-2018-0314 · Cisco NX-OS / FXOS (Cisco Fabric Services)Critical
- Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameter: Local file inclusion through directoryCVE-2018-12031 · Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameterCritical
- Dell iDRAC7/8: CGI injection giving unauthenticated remote code execution as root on the BMCCVE-2018-1207 · Dell iDRAC7/8Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.