Database/Firmware, BMC & network fabric
Linux kernel Soft-RoCE completion queue (rdma_rxe, rxe_cq_cleanup on create failure): Syzkaller-found slab
CVSS 7.8CVE-2025-38024Firmware, BMC & network fabriccurated
Impact
Syzkaller-found slab use-after-free reached straight from ib_uverbs_create_cq - the error unwind in rxe_create_cq() cleans up a queue that has already been released. Reachable by a tenant simply asking for a completion queue it knows will fail to allocate, which makes it easy to trigger repeatedly and therefore easy to shape the heap around.
Who can reach it
Local, unprivileged, via the uverbs create-CQ command on a Soft-RoCE device.
What to do
Kernel update fixing the cleanup ordering. Blacklist rdma_rxe where software RoCE is not in use.
References
Related entries
- Linux KVM/SVM - SEV/SEV-ES intra-host migration during vCPU creation: KVM permitted SEV/SEV-ES intra-host migrationCVE-2025-38455 · Linux KVM/SVM - SEV/SEV-ES intra-host migration during vCPU creationHigh
- Dell iDRAC Service Module (iSM): Buffer access with incorrect length in the in-band agent gives a low-privileged localCVE-2025-38743 · Dell iDRAC Service Module (iSM)High
- Linux bnxt_en driver (ring defaults vs traffic classes on ifdown): Memory corruption when firmware resources changeCVE-2025-39810 · Linux bnxt_en driver (ring defaults vs traffic classes on ifdown)High
- Linux kernel (drivers/infiniband/sw/rxe): Use-after-free from a race between a busy soft-RoCE task and its ownCVE-2025-40061 · Linux kernel (drivers/infiniband/sw/rxe)High
- The Linux kernel's IPMI driver message-handling layer: A use-after-free in a kernel driver reachable from the host'sCVE-2025-40202 · The Linux kernel's IPMI driver message-handling layerHigh
- Eaton UPS Companion (EUC) executable - library loading: Insecure library loading in the shipped executable givesCVE-2025-67450 · Eaton UPS Companion (EUC) executable - library loadingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.