Database/Firmware, BMC & network fabric
Linux kernel InfiniBand MAD layer (kernel RMPP receive reassembly, ib_mad): This is a pre-authentication flaw on the
Impact
This is a pre-authentication flaw on the InfiniBand management plane. The kernel started RMPP reassembly for an inbound DATA response purely on the high bits of the transaction ID, before matching the full TID and source address against any outstanding request. An unsolicited response injected onto the fabric can therefore allocate and extend kernel RMPP receive state that no local agent ever asked for - reassembly-state exhaustion and management-agent disruption driven by a peer on the same IB subnet, with no credential of any kind. On a shared fabric the adjacent 'peer' can be another tenant's node, so this is a cross-tenant reach into the layer that carries subnet-manager traffic.
Who can reach it
Adjacent network - any host able to emit MADs onto the same InfiniBand subnet, unauthenticated. That includes every compute node on a shared fabric, and any tenant that has been given umad access on such a node.
What to do
Kernel update that drops unmatched RMPP DATA responses before reassembly begins. Compensating controls are weak here: IB partitioning (pkeys) does not separate the management class, and M_Key protection only guards SMPs, not the GMP/RMPP path this affects. Patch the fabric-attached nodes.
References
Related entries
- Arista EOS: malformed packets crash the IGMP snooping agent and flood multicast to the whole VLANCVE-2026-73462 · Arista EOS IGMP snooping agentHigh
- Arista EOS: crafted packet expires multicast forwarding state early, dropping multicast trafficCVE-2026-73468 · Arista EOS multicast forwarding stateHigh
- IBM Server Firmware: unauthenticated request crashes the ASMI management web serverCVE-2026-93306 · IBM Server Firmware (ASMI web interface)High
- HPE iLO 4 / iLO 5 (remote buffer overflow): Remotely triggerable buffer overflow in the iLO firmware on both the Gen9CVE-2019-11983 · HPE iLO 4 / iLO 5 (remote buffer overflow)High
- Insyde InsydeH2O (PnpSmm shared SMM/non-SMM buffer, DMA TOCTOU): A buffer shared between SMM and non-SMM codeCVE-2022-32469 · Insyde InsydeH2O (PnpSmm shared SMM/non-SMM buffer, DMA TOCTOU)High
- Insyde InsydeH2O (FwBlockServiceSmm shared buffer, DMA TOCTOU): The firmware block service's shared buffer is racy, soCVE-2022-32470 · Insyde InsydeH2O (FwBlockServiceSmm shared buffer, DMA TOCTOU)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.