Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/ulp/rtrs): A remote client corrupts kernel linked lists on the RDMA block-storage
Impact
A remote client corrupts kernel linked lists on the RDMA block-storage server. An IB event handler is registered on every connection but never unregistered, so repeated connect/disconnect cycles leave stale handlers linked into device-wide lists - list corruption and stale-pointer execution on the target host, rated critical and network-reachable by the kernel CNA.
Who can reach it
Target-side and pre-authentication: whoever can reach the rtrs/rnbd server's listener drives it, entirely from the connection-establishment path (the CM request handler). Repeat connect/disconnect is the whole exploit. Applies to nodes exporting storage over rtrs/rnbd - if that listener is reachable from tenant networks, treat it as tenant-reachable.
What to do
No fixed release is published in this record - apply the listed stable fix commits or run a current stable kernel. Interim: firewall the rtrs/rnbd server port to the storage network only, or stop exporting rtrs targets on affected hosts until patched.
References
Related entries
- Linux kernel (drivers/infiniband/ulp/rtrs): On the RTRS server, a failure while publishing a new session's sysfsCVE-2026-64033 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server trusts a connecting client to send its session-info messageCVE-2024-50062 · Linux kernel (drivers/infiniband/ulp/rtrs)High
- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server builds an RDMA work request around a scatter-gather listCVE-2024-36476 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel (drivers/infiniband/hw/erdma): Use-after-free while accepting an inbound RDMA connection. The connectionCVE-2025-22088 · Linux kernel (drivers/infiniband/hw/erdma)Critical
- Linux kernel (drivers/infiniband/core): The iWARP connection manager frees the work objects it is currently executingCVE-2025-38211 · Linux kernel (drivers/infiniband/core)Critical
- Linux bnxt_en driver (XDP redirect list flush): List corruption in the XDP redirect path, found crashing productionCVE-2025-38246 · Linux bnxt_en driver (XDP redirect list flush)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.