Database/Firmware, BMC & network fabric
The Linux kernel's IPMI driver message-handling layer: A use-after-free in a kernel driver reachable from the host's
Impact
A use-after-free in a kernel driver reachable from the host's IPMI device nodes gives a local attacker a path to kernel memory corruption and, from there, to privilege escalation on the host. On a bare-metal GPU node the significance is the direction of travel: this is a route from an unprivileged tenant process, through the kernel, toward the interface that talks to the BMC. It is the host-side half of the out-of-band security story, and it is the half that operators tend not to inventory because it lives in the kernel rather than in firmware. The per-user message limit was miscounted in several paths, producing a use-after-free. This is the in-kernel code every host uses to talk to its own BMC over the KCS or SSIF interface.
Who can reach it
A local process on the host with access to the IPMI character devices (/dev/ipmi*). On many stock server images those permissions are looser than they should be, and any container or tenant workload given access to them is in position.
What to do
Kernel update and reboot - which on a GPU node means draining long-running training jobs, so it lands in the same expensive maintenance window as everything else kernel-level. There is a genuinely effective config-only mitigation that costs nothing: unless a workload needs in-band IPMI, do not expose /dev/ipmi* to it, and consider blacklisting the ipmi_devintf module entirely on tenant-facing bare metal. Most operators poll their BMCs over the network anyway and do not need the in-band path at all.
References
Related entries
- Eaton UPS Companion (EUC) executable - library loading: Insecure library loading in the shipped executable givesCVE-2025-67450 · Eaton UPS Companion (EUC) executable - library loadingHigh
- Linux kernel (drivers/infiniband/sw/rxe): Two failed shared-receive-queue resizes in a row panic the node. The firstCVE-2025-68379 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel mlxsw (Spectrum switch router, neighbour table): The driver stored neighbour pointers without holdingCVE-2025-68801 · Linux kernel mlxsw (Spectrum switch router, neighbour table)High
- Linux bnxt_re RoCE driver (bnxt_re_copy_err_stats out-of-bounds write): Out-of-bounds write in the Broadcom RoCECVE-2025-71092 · Linux bnxt_re RoCE driver (bnxt_re_copy_err_stats out-of-bounds write)High
- Linux kernel InfiniBand user MAD interface (ib_umad, /dev/infiniband/umad*): A process with access to the user MADCVE-2026-23243 · Linux kernel InfiniBand user MAD interface (ib_umad, /dev/infiniband/umad*)High
- Dell iDRAC Service Module (iSM) for Windows and Linux: Improper access control in the host-side iDRAC Service ModuleCVE-2026-23856 · Dell iDRAC Service Module (iSM) for Windows and LinuxHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.