Database/Firmware, BMC & network fabric
Linux kernel Soft-RoCE responder (rdma_rxe, non-SRQ receive WQE handling): A textbook time-of-check-to-time-of-use
Impact
A textbook time-of-check-to-time-of-use across the userspace/kernel RDMA boundary. For non-SRQ queue pairs the responder read work-queue-entry fields - including num_sge and the SGE array itself - directly out of the queue buffer that is mapped shared into the tenant's address space. The tenant flips num_sge or an SGE length after the kernel validates it and before it uses it, producing out-of-bounds reads in rxe_resp_check_length() and copy_data(). The attacker controls both the trigger and the timing, and the read lands wherever the forged SGE points.
Who can reach it
Local, unprivileged: a tenant with a Soft-RoCE device races its own shared receive-queue memory against the kernel responder while inbound traffic is being processed.
What to do
Kernel update introducing get_recv_wqe(), which validates num_sge and copies the WQE into a kernel-private buffer before use - the same discipline the SRQ path already had. If Soft-RoCE is not actually needed (it usually is not on nodes with real ConnectX hardware), blacklisting rdma_rxe removes the entire rxe surface without a reboot and is the fastest real mitigation.
References
Related entries
- Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.c: The shared receive queue buffer isCVE-2026-74378 · Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.cHigh
- Linux kernel (drivers/infiniband/hw/irdma): The page-address copy loop only honoured its bound when the bound wasCVE-2026-74390 · Linux kernel (drivers/infiniband/hw/irdma)High
- Dell OMSA: local heap overflow lets a low-privileged user escalate on the GPU hostCVE-2026-81474 · Dell OpenManage Server Administrator (managed node, heap-based buffer overflow)High
- Linux RDMA bnxt_re: destroy callbacks re-run against freed resources after a udata failureCVE-2026-93277 · Linux kernel RDMA/bnxt_re (udata validation in destroy/create paths)High
- Linux RDMA core: integer truncation and overflow when picking a memory-region page sizeCVE-2026-97421 · Linux kernel RDMA/umem (ib_umem_find_best_pgsz boundary handling)High
- AMI MegaRAC SPx 13 (IPMI handler / host SPI flash path): The multi-tenant bare-metal nightmareCVE-2023-34335 · AMI MegaRAC SPx 13 (IPMI handler / host SPI flash path)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.