Database/Firmware, BMC & network fabric
Linux kernel InfiniBand user MAD interface (ib_umad, /dev/infiniband/umad*): A process with access to the user MAD
Impact
A process with access to the user MAD character device can craft a write() whose declared MAD header size and RMPP header length disagree, driving the computed data_len negative. The negative length propagates into ib_create_send_mad(), where the padding calculation overshoots the segment size and produces a slab out-of-bounds memset in alloc_send_rmpp_list(). That is an attacker-influenced heap write from a device node that fabric-management tooling routinely leaves accessible, and the umad path is also the channel that speaks to the subnet manager - so heap control here sits next to the code that configures the IB fabric itself.
Who can reach it
Local write() to /dev/infiniband/umad*. Any container or user that has been granted the umad device - common on nodes running opensm, ibdiagnet, perfquery or any vendor fabric agent - can reach it without extra privilege.
What to do
Kernel update adding the explicit negative-data_len rejection in ib_umad_write(). Interim: audit which pods and which non-root users actually hold /dev/infiniband/umad* - in most clusters the answer should be 'only the fabric-management daemonset', and tightening that is a same-day change that does not need a reboot.
References
Related entries
- Dell iDRAC Service Module (iSM) for Windows and Linux: Improper access control in the host-side iDRAC Service ModuleCVE-2026-23856 · Dell iDRAC Service Module (iSM) for Windows and LinuxHigh
- Linux kernel InfiniBand core dmabuf umem (GPUDirect RDMA path): When mapping a dmabuf-backed RDMA memory region failsCVE-2026-43128 · Linux kernel InfiniBand core dmabuf umem (GPUDirect RDMA path)High
- Linux bnxt_en driver (RSS context delete logic): RSS contexts are not always freed in firmware when the driver deletesCVE-2026-43260 · Linux bnxt_en driver (RSS context delete logic)High
- Linux kernel Soft-RoCE shared receive queue (rdma_rxe, rxe_srq_from_init): If the copy_to_user() that returns the SRQCVE-2026-45852 · Linux kernel Soft-RoCE shared receive queue (rdma_rxe, rxe_srq_from_init)High
- Linux kernel (drivers/infiniband/sw/rxe): The soft-RoCE retransmit and ack timers race against queue-pair destructionCVE-2026-45910 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel RDS RDMA (memory-region cleanup on cookie copy failure): Once __rds_rdma_map() has handed theCVE-2026-46053 · Linux kernel RDS RDMA (memory-region cleanup on cookie copy failure)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.