Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): On hosts using soft-RoCE, the IB device has no DMA device, and the SMC buffer-mapping path
Impact
On hosts using soft-RoCE, the IB device has no DMA device, and the SMC buffer-mapping path dereferences that NULL pointer while setting up the receive/send buffers for an inbound connection. An unauthenticated peer connecting to the node crashes the SMC handshake worker and takes the node down - a remote availability kill with no credentials at all.
Who can reach it
Remote and pre-authentication, conditional on soft-RoCE: the crash is in smc_listen_work -> smc_buf_create -> smcr_buf_map_link, so any peer that opens a connection to an SMC-capable listener triggers it when the selected device is the software RoCE driver (rxe) rather than real hardware. Nodes that run rxe for testing, for CPU-only fallback, or inside VMs are exposed; hardware RoCE paths are not.
What to do
Boot a kernel carrying the fix commits (NULL-checks ibdev->dma_device). Interim: unload/blacklist the rdma_rxe module so soft-RoCE devices are not offered to SMC, or blacklist the smc module on those nodes.
References
Related entries
- Linux kernel (net/smc): Setsockopt() on an SMC socket copies the option value from user memory while holding the socketCVE-2026-53274 · Linux kernel (net/smc)Medium
- Linux kernel (net/smc): The early link-group cleanup path deletes the list head instead of the link group, so the groupCVE-2021-47536 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): When an SMC-R link is torn down, the kernel moves the QP to Error state and then destroys theCVE-2022-48673 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): When an incoming connection tries SMC-Rv2 and device setup fails, the listener does not resetCVE-2023-53382 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): On the server side of the SMC-R LLC handshake, adding a second link to a link group runsCVE-2023-54237 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): The server-side listen worker frees a connection outside the socket lock, so smc_conn_free()CVE-2024-56640 · Linux kernel (net/smc)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.