Database/Firmware, BMC & network fabric
Linux NFS-over-RDMA server (svcrdma, xdr_check_write_chunk): An untrusted segcount from the client is multiplied
Impact
An untrusted segcount from the client is multiplied without overflow checking when validating an RDMA Write chunk, so the buffer-overflow check itself is defeated and the server reads past the receive buffer. On an RDMA-attached storage server this is reachable directly from a tenant's HCA.
Who can reach it
Any NFS/RDMA client on the fabric - a tenant compute node with an RDMA NIC and the export mounted over rdma.
What to do
Update the storage server kernel to one with the svcrdma overflow fix and reboot. If you cannot patch quickly, fall back to NFS over TCP (proto=tcp) on the affected exports, accepting the throughput loss.
References
Related entries
- AMI AptioV UEFI BIOS: A time-of-check-to-time-of-use race in the BIOS leading to arbitrary code executionCVE-2024-54084 · AMI AptioV UEFI BIOSHigh
- Insyde InsydeH2O (UsbCoreDxe SMM module): Another SMM callout in the USB core driverCVE-2024-55567 · Insyde InsydeH2O (UsbCoreDxe SMM module)High
- GRUB2 (network config file search): grub_net_search_config_file copies a network-controlled variable with strcpyCVE-2025-0624 · GRUB2 (network config file search)High
- Linux kernel (drivers/infiniband/hw/bnxt_re): The NVMe-oF target host panics the moment a client connects.CVE-2025-21885 · Linux kernel (drivers/infiniband/hw/bnxt_re)High
- Dell Enterprise SONiC OS 4.5.0 (SSH cryptographic key): The SSH cryptographic-key weakness recurring in EnterpriseCVE-2025-38741 · Dell Enterprise SONiC OS 4.5.0 (SSH cryptographic key)High
- Fujitsu / Fsas Technologies iRMC S6 BMC (M5-generation servers): A length-boundary bug in BMC authenticationCVE-2025-65002 · Fujitsu / Fsas Technologies iRMC S6 BMC (M5-generation servers)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.