Database/Firmware, BMC & network fabric
Linux bnxt_re RoCE driver (bnxt_re_copy_err_stats out-of-bounds write): Out-of-bounds write in the Broadcom RoCE
Impact
Out-of-bounds write in the Broadcom RoCE driver's error-statistics copy, introduced when three RoCE hardware counters were added past the end of the existing array. Reading RDMA counters is something monitoring agents do constantly on an AI cluster, so the vulnerable path runs on a schedule whether or not anyone attacks it.
Who can reach it
Triggered by reading RoCE hardware counters — reachable from any local process permitted to query RDMA statistics, including monitoring agents.
What to do
Kernel/driver upgrade plus host reboot. Interim: stop polling RoCE hardware counters on Broadcom adapters, which costs you fabric observability — usually a worse trade than patching.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.