Database/Firmware, BMC & network fabric
Linux kernel - RDMA/rxe memory region translation, drivers/infiniband/sw/rxe/rxe_mr.c: Rxe mishandles memory regions
Impact
Rxe mishandles memory regions whose page size differs from the system PAGE_SIZE - it steps the page list by mr->page_size while each stored entry actually represents PAGE_SIZE of memory. The result is that an IO virtual address resolves to the wrong physical page, so a legitimate-looking remote access lands on memory outside the intended region. This is the most dangerous shape a memory-registration bug can take: the rkey check passes, the access is authorised, and the data returned or overwritten belongs to something else entirely. It matters concretely on ARM64 GPU hosts (64K pages) and anywhere hugepages are used for RDMA buffers - which is standard practice for training-job memory. A reported kernel panic is the visible symptom; silent cross-region reads and writes are the security consequence.
Who can reach it
A remote peer issues ordinary RDMA reads or writes against a memory region registered with a page size differing from the host PAGE_SIZE. No malformed packets needed - the mistranslation happens in the victim's own code path. Reachability is whatever the rxe endpoint's reachability is; combined with the rkey weaknesses described in the ReDMArk entry, an attacker who guesses into a region gets misdirected access on top of unauthorised access.
What to do
Host reboot / kernel upgrade. Interim: unload and blacklist rdma_rxe if Soft-RoCE is not in deliberate use (config change, no downtime). If rxe is required, avoid registering regions whose page size differs from PAGE_SIZE until patched - in practice that means not backing RDMA buffers with hugepages on affected kernels, which costs performance but is a same-day application/config change. Prioritise ARM64 GPU hosts and any node with 64K pages.
References
Related entries
- Linux kernel NVMe-oF TCP target (nvmet-tcp, unpropagated PDU iovec build errors): Nvmet_tcp_build_pdu_iovec() detectsCVE-2026-52989 · Linux kernel NVMe-oF TCP target (nvmet-tcp, unpropagated PDU iovec build errors)Critical
- Linux kernel - iSER (iSCSI Extensions for RDMA) target, drivers/infiniband/ulp/isert/ib_isert.c: The iSER targetCVE-2026-53176 · Linux kernel - iSER (iSCSI Extensions for RDMA) target, drivers/infiniband/ulp/isert/ib_isert.cCritical
- uefi-firmware-parser: unvalidated bit lengths in MakeTable() smash the stack on crafted firmwareCVE-2026-54333 · uefi-firmware-parser Tiano decompressor (MakeTable bit-length validation)Critical
- uefi-firmware-parser: ReadCLen() overruns the 510-entry mCLen heap array on crafted firmwareCVE-2026-54334 · uefi-firmware-parser Tiano decompressor (ReadCLen mCLen bounds)Critical
- Dell SmartFabric OS10 before 10.6.1.3: session fixation lets a remote unauthenticated attacker steal a sessionCVE-2026-63695 · Dell SmartFabric OS10 (session handling in the management interface)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): On the RTRS server, a failure while publishing a new session's sysfsCVE-2026-64033 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.