Database/Firmware, BMC & network fabric
Linux kernel - SRP (SCSI RDMA Protocol) initiator, drivers/infiniband/ulp/srp/ib_srp.c: The SRP initiator copied the
Impact
The SRP initiator copied the sense data out of an SRP_RSP without bounding the copy by the length actually received, so a malicious or compromised SRP target can overrun the initiator's buffer and read host kernel memory or crash the node. This inverts the usual threat direction - here the storage array attacks its clients. In a GPU cluster where an array or a software SRP target serves many compute nodes, one compromised target reaches every node that mounts from it, which is a fleet-wide blast radius from a single storage compromise.
Who can reach it
The attacker controls or has compromised an SRP target the victim connects to, and returns an SRP_RSP whose declared sense length exceeds what was received. No credentials on the victim are needed beyond it being a normal client of the target. Also reachable by an attacker who can inject into the SRP connection using the RDMA packet-injection primitives.
What to do
Host reboot / kernel upgrade on all SRP initiator nodes. Interim: verify SRP targets are on a management-isolated storage fabric with per-tenant partitioning so an untrusted party cannot stand up a rogue target and attract connections; that is a switch/SM config change. If SRP is legacy in your environment and NVMe-oF has replaced it, unload ib_srp and remove the initiator configuration entirely - a config change that eliminates the surface.
References
Related entries
- Dell SmartFabric OS10 before 10.6.1.3: code downloaded without integrity check allows code executionCVE-2026-63696 · Dell SmartFabric OS10 (code download without integrity check)Critical
- Linux kernel - RDMA/rtrs server (RDMA Transport, used by RNBD block storage), drivers/infiniband/ulp/rtrs/rtrs-srv.cCVE-2026-64269 · Linux kernel - RDMA/rtrs server (RDMA Transport, used by RNBD block storage), drivers/infiniband/ulp/rtrs/rtrs-srv.cCritical
- AMD Secure Processor (Ryzen / Ryzen Pro / Ryzen Mobile): Insufficient access control on the Secure Processor lets codeCVE-2018-8931 · AMD Secure Processor (Ryzen / Ryzen Pro / Ryzen Mobile)Critical
- AMD Secure Processor (Ryzen / Ryzen Pro): The same class of Secure Processor access-control failure as RYZENFALL-1CVE-2018-8932 · AMD Secure Processor (Ryzen / Ryzen Pro)Critical
- Promontory chipset firmware (AMD Ryzen / Ryzen Pro platforms): A backdoor in the Promontory chipset firmware. TheCVE-2018-8934 · Promontory chipset firmware (AMD Ryzen / Ryzen Pro platforms)Critical
- AMD EPYC / Ryzen - Platform Security Processor privilege escalation: A direct privilege escalation into the PlatformCVE-2018-8936 · AMD EPYC / Ryzen - Platform Security Processor privilege escalationCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.