Database/Firmware, BMC & network fabric
Linux kernel RDMA core (UVERBS_ATTR_ALLOC_DMAH_CPU_ID, DMA handle allocation): The cpu_id a tenant passes when
Impact
The cpu_id a tenant passes when allocating a DMA handle goes straight into cpumask_test_cpu() with no range check, so it becomes an unbounded bit index into the cpumask bitmap - an out-of-bounds kernel read at an offset the tenant chooses. On kernels built with CONFIG_DEBUG_PER_CPU_MAPS the same input trips a WARN_ON_ONCE, which on a panic_on_warn fleet (common in hyperscale and neocloud images, because operators want crash dumps rather than silent corruption) converts an unprivileged ioctl into a node reboot - one tenant evicting every other job on the box.
Who can reach it
Local ioctl on /dev/infiniband/uverbs* by any RDMA-capable tenant. Unprivileged.
What to do
Kernel update rejecting cpu_id values that are not below nr_cpu_ids. If you run panic_on_warn fleet-wide, note that this class of bug turns any WARN reachable from an unprivileged syscall into a tenant-triggered node kill - worth reviewing that policy alongside the patch.
References
Related entries
- Dell OpenManage Enterprise: SQL injection reachable by a low-privileged remote userCVE-2026-56088 · Dell OpenManage Enterprise (web console, SQL injection)High
- Linux kernel InfiniBand MAD layer (kernel RMPP receive reassembly, ib_mad): This is a pre-authentication flaw on theCVE-2026-68425 · Linux kernel InfiniBand MAD layer (kernel RMPP receive reassembly, ib_mad)High
- Arista EOS: malformed packets crash the IGMP snooping agent and flood multicast to the whole VLANCVE-2026-73462 · Arista EOS IGMP snooping agentHigh
- Arista EOS: crafted packet expires multicast forwarding state early, dropping multicast trafficCVE-2026-73468 · Arista EOS multicast forwarding stateHigh
- IBM Server Firmware: unauthenticated request crashes the ASMI management web serverCVE-2026-93306 · IBM Server Firmware (ASMI web interface)High
- HPE iLO 4 / iLO 5 (remote buffer overflow): Remotely triggerable buffer overflow in the iLO firmware on both the Gen9CVE-2019-11983 · HPE iLO 4 / iLO 5 (remote buffer overflow)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.