Database/Kernel, userspace & hypervisor
Linux kernel RTRS client (rtrs-clt init_conns connection-id bound): When connection setup fails partway through, the
Impact
When connection setup fails partway through, the cleanup loop starts at cid == con_num rather than con_num - 1 and indexes one past the end of the connection array. RTRS is the RDMA transport under RNBD block devices, so this is the block-storage path of an RDMA cluster; the kernel CNA rates it network-reachable and unauthenticated, because a peer that makes connection establishment fail at the right point drives the out-of-bounds access remotely.
Who can reach it
Remote. A server-side peer that fails connection establishment partway through the multi-connection setup.
What to do
Kernel update resetting cid to con_num - 1 before the cleanup loop. If RNBD/RTRS is not in use, keep the modules unloaded.
References
Related entries
- Linux kernel SMC-R/SMC-D (CLC proposal parsing, v2_ext_offset / eid_cnt / ism_gid_cnt): The same unvalidated-offsetCVE-2024-49568 · Linux kernel SMC-R/SMC-D (CLC proposal parsing, v2_ext_offset / eid_cnt / ism_gid_cnt)Critical
- Linux kernel mlx5_core kTLS TX offload: The kTLS TX path mixes get_page() and page_ref_inc() when acquiring referencesCVE-2024-53138 · Linux kernel mlx5_core kTLS TX offloadCritical
- Linux kernel (net/smc): The server-side listen worker frees a connection outside the socket lock, so smc_conn_free()CVE-2024-56640 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): A link-down work item can be queued before the link group is freed but run after, so the workerCVE-2024-56718 · Linux kernel (net/smc)Critical
- Linux kernel (net/tls): The synchronous decrypt path shared refcounting and completion state with the async path, so aCVE-2024-58240 · Linux kernel (net/tls)Critical
- Linux kernel (drivers/nvme/target): The target disables a namespace without waiting for in-flight I/O to drain, so aCVE-2025-21850 · Linux kernel (drivers/nvme/target)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.