Database/Firmware, BMC & network fabric
Linux kernel - RDMA/rxe (Soft-RoCE) receive path, drivers/infiniband/sw/rxe/rxe_recv.c: Rxe_rcv() checked only that an
Impact
Rxe_rcv() checked only that an inbound packet was at least header_size bytes, but payload_size() then subtracts the attacker-controlled BTH pad field and the ICRC size from the packet length. A short packet, or one carrying a forged non-zero pad, makes that subtraction underflow and hands a bogus length to everything downstream in the receive path. Since Soft-RoCE rides UDP/4791, a single unauthenticated datagram from anywhere that can reach the node crashes or corrupts the kernel - no connection, no handshake, no credentials. On a shared fabric one packet from one tenant takes down a GPU node and every job on it.
Who can reach it
Send a crafted UDP datagram to port 4791 on any host with rdma_rxe loaded. The BTH pad field is set by the attacker, so even a packet long enough to pass the header check can drive the payload length negative. Entirely pre-authentication and reachable from any source the network permits, including across routed segments if 4791 is not filtered.
What to do
Host reboot / kernel upgrade. Faster and cheaper: unload and blacklist rdma_rxe on every node that is not deliberately running Soft-RoCE (config change, zero downtime) - this closes the entire rxe family of remote packet bugs. If rxe is genuinely required, firewall UDP/4791 to known peers immediately as a stopgap, then upgrade the kernel on a rolling drain. Note the follow-on CVE-2026-46133 shows the first attempt at this fix was incomplete, so verify you are on a kernel carrying both.
References
Related entries
- Linux kernel - SRP (SCSI RDMA Protocol) initiator, drivers/infiniband/ulp/srp/ib_srp.c: The SRP initiator copied theCVE-2026-53186 · Linux kernel - SRP (SCSI RDMA Protocol) initiator, drivers/infiniband/ulp/srp/ib_srp.cCritical
- Dell SmartFabric OS10 before 10.6.1.3: code downloaded without integrity check allows code executionCVE-2026-63696 · Dell SmartFabric OS10 (code download without integrity check)Critical
- Linux kernel - RDMA/rtrs server (RDMA Transport, used by RNBD block storage), drivers/infiniband/ulp/rtrs/rtrs-srv.cCVE-2026-64269 · Linux kernel - RDMA/rtrs server (RDMA Transport, used by RNBD block storage), drivers/infiniband/ulp/rtrs/rtrs-srv.cCritical
- AMD Secure Processor (Ryzen / Ryzen Pro / Ryzen Mobile): Insufficient access control on the Secure Processor lets codeCVE-2018-8931 · AMD Secure Processor (Ryzen / Ryzen Pro / Ryzen Mobile)Critical
- AMD Secure Processor (Ryzen / Ryzen Pro): The same class of Secure Processor access-control failure as RYZENFALL-1CVE-2018-8932 · AMD Secure Processor (Ryzen / Ryzen Pro)Critical
- Promontory chipset firmware (AMD Ryzen / Ryzen Pro platforms): A backdoor in the Promontory chipset firmware. TheCVE-2018-8934 · Promontory chipset firmware (AMD Ryzen / Ryzen Pro platforms)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.