Database/Firmware, BMC & network fabric
Linux kernel mlx5_ib (InfiniBand/RoCE completion queue polling): mlx5_poll_one() compares the firmware's QP number
Impact
mlx5_poll_one() compares the firmware's QP number against the wrong structure's QP number, so the wrong queue pair is used to handle a completion, leading to a NULL dereference. Anyone already on the InfiniBand subnet can drive it: unsolicited SMP/GMP/CM management datagrams land on QP0/QP1 and generate the completions, and MAD reception on an IB fabric is entirely unauthenticated. On a shared InfiniBand fabric this is a way for any attached node to crash other nodes' RDMA stacks.
Who can reach it
Any node on the same InfiniBand subnet, unauthenticated - no login on the target, just fabric attachment. Adjacent-network attack vector.
What to do
Upgrade the host kernel to 6.15 or a stable backport (5.4.292, 5.10.236, 5.15.180, 6.1.134, 6.6.87, 6.12.23, 6.13.11, 6.14.2). Rolling reboot of every InfiniBand/RoCE host. Complementary control: enforce partition keys and restrict which nodes can attach to the subnet - this bug is a strong argument for not treating an IB fabric as a trusted flat network.
References
Related entries
- Dell SmartFabric OS10 (command injection): Second command-injection path in the same OS10 advisory, givingCVE-2025-46427 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): A low-privileged remote attacker executes code on the switch OSCVE-2025-46428 · Dell SmartFabric OS10 (command injection)High
- ATEN eco DC (DCIM/environmental management platform): The web interface doesn't check a user's assigned roleCVE-2025-6685 · ATEN eco DC (DCIM/environmental management platform)High
- Lenovo XClarity Orchestrator (alternate communication channel): An attacker on the LXCO network segment manipulatesCVE-2025-8557 · Lenovo XClarity Orchestrator (alternate communication channel)High
- Lenovo XClarity Integrator for Windows Admin Center (PowerShell command injection): PowerShell command injectionCVE-2026-14371 · Lenovo XClarity Integrator for Windows Admin Center (PowerShell command injection)High
- OpenBMC phosphor-net-ipmid: session authorization can be swapped to another account without re-authenticatingCVE-2026-16140 · OpenBMC phosphor-net-ipmid (IPMI 2.0 RAKP session authorization)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.