Database/Firmware, BMC & network fabric
Linux kernel InfiniBand core (ib_uverbs post_send): ib_uverbs_post_send() takes the work-queue-entry size straight
Impact
ib_uverbs_post_send() takes the work-queue-entry size straight from userspace with no validation, allocates that size, then reads fields past the allocation - an out-of-bounds read of the kernel heap that leaks kernel memory to an unprivileged process. The receive path validated this; the send path did not. Any tenant process holding an RDMA verbs handle - which on a GPU cluster is every job using NCCL, UCX or MPI - can read host kernel memory.
Who can reach it
A local unprivileged user with an open RDMA verbs device handle. On a shared GPU node that is any tenant running a distributed training job.
What to do
Upgrade the host kernel to 7.0 or a stable backport (5.10.252, 5.15.202, 6.1.165, 6.6.128, 6.12.75, 6.18.14, 6.19.4). Rolling reboot of every node that exposes /dev/infiniband/uverbs* to workloads - which is all of them on an RDMA cluster.
References
Related entries
- Linux kernel RDMA core (UVERBS_ATTR_ALLOC_DMAH_CPU_ID, DMA handle allocation): The cpu_id a tenant passes whenCVE-2026-53187 · Linux kernel RDMA core (UVERBS_ATTR_ALLOC_DMAH_CPU_ID, DMA handle allocation)High
- Dell OpenManage Enterprise: SQL injection reachable by a low-privileged remote userCVE-2026-56088 · Dell OpenManage Enterprise (web console, SQL injection)High
- Linux kernel InfiniBand MAD layer (kernel RMPP receive reassembly, ib_mad): This is a pre-authentication flaw on theCVE-2026-68425 · Linux kernel InfiniBand MAD layer (kernel RMPP receive reassembly, ib_mad)High
- Arista EOS: malformed packets crash the IGMP snooping agent and flood multicast to the whole VLANCVE-2026-73462 · Arista EOS IGMP snooping agentHigh
- Arista EOS: crafted packet expires multicast forwarding state early, dropping multicast trafficCVE-2026-73468 · Arista EOS multicast forwarding stateHigh
- IBM Server Firmware: unauthenticated request crashes the ASMI management web serverCVE-2026-93306 · IBM Server Firmware (ASMI web interface)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.