Database/Firmware, BMC & network fabric
Linux kernel bnxt_re: doorbell page allocation reports success when ioremap fails, leaving unwound driver state
Impact
bnxt_qplib_alloc_dpi() returned success even when the ioremap of the doorbell page failed, so the RDMA stack continued with a doorbell mapping that does not exist and with the allocation only partly unwound. On a GPU node this driver is the RoCE path used by Broadcom NICs for NCCL/RDMA traffic, so the affected code runs on every QP/doorbell-page allocation by any process holding an RDMA device. The practical exposure is a kernel fault or corrupted driver state on the ioremap failure path rather than a directly steerable primitive; ioremap failure normally requires memory or vmalloc-address-space pressure. The kernel maintainers' CVSS places it at 9.2 with changed scope, but the record gives no exploitation detail beyond the missing rollback, so treat the severity as the error path's worst case rather than a demonstrated attack.
Who can reach it
Local. A process that can open an RDMA device (verbs character device) and allocate doorbell pages, under conditions where ioremap fails. No remote or unauthenticated path is described in the record. Not reachable on nodes with no bnxt_re device.
What to do
Pick up the fixed stable kernel for your series (five stable commits are linked from the record; the record names no single fixed version). Applying it means rebooting each node with a Broadcom RoCE NIC, which on a GPU fleet is a drain-and-reboot per node. Nodes that use Mellanox/ConnectX RDMA instead of bnxt_re are unaffected and need no window.
References
Related entries
- Arista EOS gNPSI: unauthenticated request yields arbitrary code execution on the switchCVE-2026-73456 · Arista EOS (gNPSI - gRPC Network Packet Sampling Interface)Critical
- Arista EOS: crafted packet brings down authenticated BFD sessions and triggers routing changesCVE-2026-73458 · Arista EOS BFD (authenticated session packet handling)Critical
- MikroTik RouterOS: SSH username argument handling lets an unauthenticated client escalate policy privilegesCVE-2026-86060 · MikroTik RouterOS (SSH login helper, policy mask handling)Critical
- Tripp Lite PDUMH15AT / SU750XL PDU: The PDU accepts unauthenticated POST requests to its /Forms/ endpoints, which canCVE-2019-16261 · Tripp Lite PDUMH15AT / SU750XL PDUCritical
- IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handling: The original default BMC password kept workingCVE-2019-4169 · IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handlingCritical
- Lanner IAC-AST2500A BMC firmware: An authenticated BMC user escalates to root code execution on the controllerCVE-2021-26731 · Lanner IAC-AST2500A BMC firmwareCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.