Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/ulp/rtrs): On the RTRS server, a failure while publishing a new session's sysfs
Impact
On the RTRS server, a failure while publishing a new session's sysfs entries drops the last reference to the session object and then keeps using it - a use-after-free in the storage target's own address space, driven by a peer establishing a session. The CNA scores it network-reachable with no privileges and full compromise.
Who can reach it
Any host that can reach the RTRS server on the storage fabric - i.e. a tenant node or a compromised client of an RNBD/RTRS block export - triggers this by opening sessions and driving the setup failure path. Requires the rtrs_server module loaded, so it only affects nodes acting as RTRS/RNBD targets.
What to do
Update to 5.15.209 or later, or a stable kernel carrying 01e42aabaf76 / 548f3956e53a, and reboot. Interim: stop exporting RTRS/RNBD targets from the affected nodes, or restrict which fabric peers can reach the RTRS listener until patched.
References
Related entries
- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server trusts a connecting client to send its session-info messageCVE-2024-50062 · Linux kernel (drivers/infiniband/ulp/rtrs)High
- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server builds an RDMA work request around a scatter-gather listCVE-2024-36476 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): A remote client corrupts kernel linked lists on the RDMA block-storageCVE-2025-21805 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.c: The siw receive path decodesCVE-2026-64102 · Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.cCritical
- Linux kernel - RDMA/siw (soft-iWARP), drivers/infiniband/sw/siw/siw_qp_rx.c: Siw places inbound Read Response segmentsCVE-2026-64268 · Linux kernel - RDMA/siw (soft-iWARP), drivers/infiniband/sw/siw/siw_qp_rx.cCritical
- Linux kernel - NVMe-oF RDMA target, drivers/nvme/target/rdma.c: Nvmet_rdma_use_inline_sg() accepted any host-controlledCVE-2026-72129 · Linux kernel - NVMe-oF RDMA target, drivers/nvme/target/rdma.cCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.