Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/sw/rxe): Two failed shared-receive-queue resizes in a row panic the node. The first
Impact
Two failed shared-receive-queue resizes in a row panic the node. The first failure leaves the queue pointer null, and the second call dereferences it while validating attributes - a deterministic, unprivileged kernel crash that takes the whole shared host down.
Who can reach it
A tenant container holding /dev/infiniband/uverbs* on a node with soft-RoCE (rdma_rxe) loaded: call the standard SRQ-modify verb twice with a size that makes the queue reallocation fail. Entirely tenant-controlled, no race to win, no fabric peer needed. Hardware HCAs do not run this code.
What to do
No fixed release is published in this record - apply the listed stable fix commits or run a current stable kernel. Interim: blacklist/unload rdma_rxe unless soft-RoCE is deliberately in use, and keep /dev/infiniband/* out of containers that do not need verbs.
References
Related entries
- Linux kernel (drivers/infiniband/sw/rxe): The soft-RoCE retransmit and ack timers race against queue-pair destructionCVE-2026-45910 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel (drivers/infiniband/sw/rxe): A null-pointer dereference panics the node whenever queue-pair creation failsCVE-2022-50885 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel (drivers/infiniband/sw/rxe): Any tenant that can open an RDMA verbs device can oops the node. A queue-pairCVE-2022-50127 · Linux kernel (drivers/infiniband/sw/rxe)Medium
- Linux kernel (drivers/infiniband/sw/rxe): Soft-RoCE queue-pair cleanup drains send and receive work queues that aCVE-2023-53528 · Linux kernel (drivers/infiniband/sw/rxe)Medium
- Linux kernel (drivers/infiniband/sw/rxe): If soft-RoCE queue-pair creation fails partway, the unwind path runs cleanupCVE-2023-54028 · Linux kernel (drivers/infiniband/sw/rxe)Medium
- Linux kernel (drivers/infiniband/sw/rxe): When soft-RoCE queue-pair initialisation fails, the QP structure is left fullCVE-2021-47078 · Linux kernel (drivers/infiniband/sw/rxe)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.