Database/Firmware, BMC & network fabric
Linux kernel SoftiWARP receive path (siw_qp_rx, siw_tcp_rx_data header processing): When siw_get_hdr() rejects a header
Impact
When siw_get_hdr() rejects a header with -EINVAL before the receive context has been established, the error path still dereferences qp->rx_fpdu->more_ddp_segs on a NULL rx_fpdu. A remote peer sending a deliberately invalid DDP/MPA header crashes the node. On a shared training node that is one unauthenticated packet evicting every co-resident job.
Who can reach it
Remote, unauthenticated. Any peer that can reach the siw TCP listener.
What to do
Kernel update guarding the more_ddp_segs check on rx_fpdu being present. Same immediate mitigation as the other siw issues: unload the siw module where SoftiWARP is not in use.
References
Related entries
- GNU FreeIPMI's ipmi-oem tool before version 1.6.17: The direction of trust is what makes this operator-relevantCVE-2026-33554 · GNU FreeIPMI's ipmi-oem tool before version 1.6.17High
- Cocos AI - attested TLS (aTLS) on AMD SEV-SNP and Intel TDX: The attested-TLS implementation is vulnerable to a relayCVE-2026-33697 · Cocos AI - attested TLS (aTLS) on AMD SEV-SNP and Intel TDXHigh
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When an XDP program shrinks a multi-fragment receive bufferCVE-2026-43464 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.c: Atomic_write_reply() dereferencesCVE-2026-46114 · Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.cHigh
- Linux kernel - RDMA/rxe (Soft-RoCE) ICRC processing, drivers/infiniband/sw/rxe: The follow-up to CVE-2026-46043, andCVE-2026-46133 · Linux kernel - RDMA/rxe (Soft-RoCE) ICRC processing, drivers/infiniband/sw/rxeHigh
- GNU FreeIPMI ipmi-oem before 1.6.18: Same shape as its predecessor and the same fleet consequence: a hostile BMCCVE-2026-50031 · GNU FreeIPMI ipmi-oem before 1.6.18High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.