Database/Firmware, BMC & network fabric
Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/lib): Every memory-key allocation carrying a steering-tag hint
Impact
Every memory-key allocation carrying a steering-tag hint leaks a small kernel structure when the key is released. A tenant that registers and deregisters RDMA memory regions in a loop grows the host's kernel slab without bound until the node runs out of memory - a noisy-neighbour path from an unprivileged RDMA workload to an out-of-memory event for every tenant on the box.
Who can reach it
A tenant container holding /dev/infiniband/uverbs* that churns memory-region registration/deregistration on an mlx5 device drives it directly; this is the normal steady-state path, not an error path. Conditional on the mkeys carrying TPH steering-tag hints, which the RDMA stack sets for hinted registrations on supporting hardware.
What to do
Update to a kernel carrying the fix on your stream. Interim: cap tenant RDMA registration rates where possible, monitor kernel slab growth on nodes exporting verbs to tenants, and withhold /dev/infiniband/* from workloads that do not need it.
References
Related entries
- Dell OMSA: missing authentication on a critical function lets a local user crash the management agentCVE-2026-81441 · Dell OpenManage Server Administrator (OMSA) managed-node agentMedium
- Dell OMSA: partial string comparison flaw lets a low-privileged local user cause a denial of serviceCVE-2026-81479 · Dell OpenManage Server Administrator (OMSA) managed-node agentMedium
- Opengear console server (serial port logging): Stored XSS injected from a device *connected to* a serial portCVE-2019-14456 · Opengear console server (serial port logging)Medium
- AMD Secure Processor bootloader - SPIROM upgrade path: An attacker who can drive the SPIROM upgrade path can passCVE-2025-48515 · AMD Secure Processor bootloader - SPIROM upgrade pathMedium
- Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-F: Full control of the instruction pointer inside the BMC's firmware OSCVE-2025-7623 · Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-FMedium
- AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11): The SEV implementation in PSPCVE-2019-9836 · AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.