Database/Firmware, BMC & network fabric
Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.c: Atomic_write_reply() dereferences
Impact
Atomic_write_reply() dereferences 8 bytes at the payload address unconditionally, while the rkey check accepted an ATOMIC_WRITE with a RETH length of zero. A remote initiator sending a zero-length ATOMIC_WRITE makes the responder read 8 bytes past the logical end of the packet into the socket buffer's tailroom and then write those bytes into the attacker's own memory region. That is a clean remote read primitive: four bytes of uninitialised kernel memory disclosed to the attacker per probe, repeatable at will, ideal for defeating KASLR or harvesting kernel pointers before a heavier exploit. The IB specification defines ATOMIC_WRITE as exactly 8 bytes, so anything else was always protocol-invalid.
Who can reach it
Remote initiator on an rxe connection sets the RETH length to 0 on an ATOMIC_WRITE and reads back the responder's reply, which now contains kernel tailroom bytes. Repeat to accumulate a memory-disclosure oracle. No local privilege and no authentication beyond reaching the Soft-RoCE endpoint.
What to do
Host reboot / kernel upgrade. Same family control as the other rxe findings: blacklist and unload rdma_rxe where Soft-RoCE is not intentionally deployed, which is a config change with no downtime and removes this along with the rest. Where rxe is in use, upgrade the kernel and reboot on rolling drain, and firewall UDP/4791 to known peers in the meantime.
References
Related entries
- Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.c: The shared receive queue buffer isCVE-2026-74378 · Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.cHigh
- Linux kernel - RDMA/rxe (Soft-RoCE) ICRC processing, drivers/infiniband/sw/rxe: The follow-up to CVE-2026-46043, andCVE-2026-46133 · Linux kernel - RDMA/rxe (Soft-RoCE) ICRC processing, drivers/infiniband/sw/rxeHigh
- GNU FreeIPMI ipmi-oem before 1.6.18: Same shape as its predecessor and the same fleet consequence: a hostile BMCCVE-2026-50031 · GNU FreeIPMI ipmi-oem before 1.6.18High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): Every time an XDP_TX transmit fails because the XDP sendCVE-2026-53229 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Two CPUs write to the internal control send queue withoutCVE-2026-64210 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/infiniband/hw/mlx5): When on-demand-paging translation-table population fails, the UMR pathCVE-2026-74396 · Linux kernel (drivers/infiniband/hw/mlx5)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.