Database/Firmware, BMC & network fabric
Linux kernel (drivers/infiniband/sw/siw): Soft-iWARP published a new queue pair into the lookup table before its
Impact
Soft-iWARP published a new queue pair into the lookup table before its queues, completion-queue pointers and state were set up, so a concurrent QP-number lookup reaches a half-built object and follows uninitialised pointers. An attacker who wins the window gets kernel memory corruption from unprivileged userspace.
Who can reach it
An unprivileged process on a node with the siw module loaded creates a QP in one thread while a second thread - or an inbound iWARP segment from a fabric peer that resolves the freshly allocated QP number - looks it up. No hardware RDMA adapter needed, which is exactly why siw is dangerous to leave loaded in tenant containers.
What to do
No fixed version is listed in the record - take the stable kernel carrying 3c9d12821996 (or 3ff82e3841ec / 36e91a58397c) and reboot. Interim: unload and blacklist siw on nodes that do not need soft-iWARP.
References
Related entries
- Linux kernel (drivers/infiniband/sw/siw): A remote peer crashes the node during connection setup. When the MPACVE-2022-50136 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/siw): When soft-iWARP fails to process an inbound MPA connection requestCVE-2023-52513 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/siw): A tenant gets an out-of-bounds kernel array read using values it controls.CVE-2022-50736 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/siw): A remote peer turns a connection drop into a kernel use-after-free. TheCVE-2022-50666 · Linux kernel (drivers/infiniband/sw/siw)Critical
- Linux kernel (drivers/infiniband/sw/siw): Soft-iWARP memory-region allocation stores the memory object into the MR andCVE-2021-47012 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/hw/irdma): The pseudo memory regions that back a QP/CQ/SRQ have no real hardware keyCVE-2026-68419 · Linux kernel (drivers/infiniband/hw/irdma)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.