Database/Control plane, storage & DevOps
Linux octeontx2-af (VF rx-mode affecting PF promiscuous state): A VF setting its receive mode causes the *physical
Impact
A VF setting its receive mode causes the *physical function's* promiscuous and all-multicast MCAM rules to be deleted, because the enable/disable APIs operate on the PF even when the request arrives over a VF's mailbox. One tenant's VF can therefore change what the host's own interface receives — either blinding the operator's PF, or, in the inverse direction, the coupling means VF-driven rx-mode changes have effects outside the VF's own scope. On a shared OCTEON adapter that is one tenant reaching across the SR-IOV boundary into the host's receive path.
Who can reach it
A tenant with an assigned OCTEON VF issuing a normal nix_set_rx_mode mailbox request — no exploit primitive needed, just the ordinary API.
What to do
Kernel upgrade plus host reboot across OCTEON-equipped nodes. No config workaround; the coupling is in the mailbox handler. Rolling drain per node.
References
Related entries
- Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingCVE-2015-2291 · Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingHigh
- IBM Spectrum Scale daemon (GSKit cryptographic library dependency): A local attacker takes control of the SpectrumCVE-2018-1431 · IBM Spectrum Scale daemon (GSKit cryptographic library dependency)High
- Arista CloudVision Portal (Configlet Builder API): A read-only CloudVision user escapes their permissions throughCVE-2019-18181 · Arista CloudVision Portal (Configlet Builder API)High
- MUNGE (SUSE/openSUSE packaging): The munge package's install scripts follow symlinks, so a local attacker who controlsCVE-2019-3691 · MUNGE (SUSE/openSUSE packaging)High
- IBM Spectrum Scale administrative command path: A local unprivileged user becomes root on a Storage Scale node byCVE-2019-4558 · IBM Spectrum Scale administrative command pathHigh
- targetcli-fb 2.1.50/2.1.51 and rtslib-fb through 2.1.72 (configuration tooling for the Linux LIO iSCSI/NVMe-oF target)CVE-2020-10699 · targetcli-fb 2.1.50/2.1.51 and rtslib-fb through 2.1.72 (configuration tooling for the Linux LIO iSCSI/NVMe-oF target)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.