Database/Firmware, BMC & network fabric
Linux kernel - RDMA/rxe (Soft-RoCE) ICRC processing, drivers/infiniband/sw/rxe: The follow-up to CVE-2026-46043, and
Impact
The follow-up to CVE-2026-46043, and the reason to check you have both. The rxe_opcode[] table has 256 entries but only defined IB opcodes are populated; an undefined opcode such as 0xff reads a zero-initialised entry, so the length check added by the previous fix degenerates to a comparison against zero and stops constraining the packet length. rxe_icrc_hdr() then computes length minus the BTH size, which underflows, producing an out-of-bounds read. One unauthenticated UDP packet still panics the node. The defect predates the earlier fix and reaches back to the original Soft-RoCE driver, so any kernel with rxe loaded has carried it for years.
Who can reach it
A single UDP datagram to port 4791 carrying an opcode not defined in the IB specification. No connection state, no authentication, no prior contact with the target. Trivially scriptable and trivially fleet-wide.
What to do
Host reboot / kernel upgrade to a kernel carrying this fix specifically - patching only CVE-2026-46043 leaves you exposed. As with the rest of the rxe family, the zero-cost control is to blacklist and unload rdma_rxe where Soft-RoCE is not in use (config change, no downtime), which is the right answer on essentially every production GPU node with real RDMA hardware. Where rxe must stay, restrict UDP/4791 at the host firewall and switch ACLs to known peers while the kernel rollout proceeds.
References
Related entries
- GNU FreeIPMI ipmi-oem before 1.6.18: Same shape as its predecessor and the same fleet consequence: a hostile BMCCVE-2026-50031 · GNU FreeIPMI ipmi-oem before 1.6.18High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): Every time an XDP_TX transmit fails because the XDP sendCVE-2026-53229 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Two CPUs write to the internal control send queue withoutCVE-2026-64210 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/infiniband/hw/mlx5): When on-demand-paging translation-table population fails, the UMR pathCVE-2026-74396 · Linux kernel (drivers/infiniband/hw/mlx5)High
- Dell OMSA: unauthenticated path traversal exposes arbitrary files from the managed nodeCVE-2026-81481 · Dell OpenManage Server Administrator (path traversal, unauthenticated)High
- FreeIPMI ipmi-oem: stack buffer over-read when a BMC returns a short Fujitsu SEL responseCVE-2026-85505 · FreeIPMI ipmi-oem (Fujitsu get-sel-entry-long-text handler)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.