GPU VulnDB

Database/Firmware, BMC & network fabric

Linux kernel (drivers/infiniband/ulp/rtrs): On the RTRS server, a failure while publishing a new session's sysfs

CVE-2026-64033Firmware, BMC & network fabriccurated

Impact

On the RTRS server, a failure while publishing a new session's sysfs entries drops the last reference to the session object and then keeps using it - a use-after-free in the storage target's own address space, driven by a peer establishing a session. The CNA scores it network-reachable with no privileges and full compromise.

Who can reach it

Any host that can reach the RTRS server on the storage fabric - i.e. a tenant node or a compromised client of an RNBD/RTRS block export - triggers this by opening sessions and driving the setup failure path. Requires the rtrs_server module loaded, so it only affects nodes acting as RTRS/RNBD targets.

What to do

Update to 5.15.209 or later, or a stable kernel carrying 01e42aabaf76 / 548f3956e53a, and reboot. Interim: stop exporting RTRS/RNBD targets from the affected nodes, or restrict which fabric peers can reach the RTRS listener until patched.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.