Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/core): IWARP port-mapper netlink attributes were accepted as plain strings with no
Impact
IWARP port-mapper netlink attributes were accepted as plain strings with no guarantee of a NUL terminator, then handed to strcmp and %s. A crafted attribute makes the kernel read past the attribute into adjacent memory - kernel memory disclosure into log output and comparisons, or an oops. The CNA scored it as requiring no privileges.
Who can reach it
Requires the ability to send RDMA_NL_IWPM netlink messages, normally the host's iwpmd port-mapper daemon. Relevant on iWARP-capable nodes (irdma in iWARP mode, cxgb4, siw); a tenant with CAP_NET_ADMIN in a non-user-namespaced net namespace, or anything that can impersonate the port mapper, reaches it. Not reachable from the fabric.
What to do
Update to a stable kernel carrying fcd07d3b8ee7 (or 87111356d58d / abda65bdd130) and reboot. Interim: do not grant CAP_NET_ADMIN over the host netlink namespace to tenant workloads, and disable iWARP mode where the fabric does not require it.
References
Related entries
- Linux kernel (drivers/infiniband/core): The core set the send and receive completion-queue pointers on a queue pairCVE-2021-47196 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/infiniband/core): The RDMA connection-manager state machine can be driven in a circle so twoCVE-2021-47391 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/infiniband/core): A heap use-after-free in the userspace RDMA connection-manager interface.CVE-2022-48726 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/infiniband/core): An unprivileged tenant corrupts RDMA connection-manager state and lands aCVE-2022-48925 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/infiniband/core): A 32-bit advance counter in the core RDMA block iterator wraps when a singleCVE-2023-53026 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/infiniband/core): When the IOMMU coalesces a large memory registration into one block spanningCVE-2026-53133 · Linux kernel (drivers/infiniband/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.