Database/Kernel, userspace & hypervisor
Linux kernel (drivers/nvme/host): The multipath current-path array is sized by the count of possible NUMA nodes but
Impact
The multipath current-path array is sized by the count of possible NUMA nodes but indexed by the actual NUMA node ID. On any machine whose node IDs are sparse rather than 0..N-1, ordinary I/O writes eight bytes past the end of the slab allocation - silent heap corruption of whatever object sits next, driven by the normal data path rather than by an error case.
Who can reach it
No attacker action is required beyond running I/O: any tenant's reads and writes through an NVMe multipath device index the array by the NUMA node of the CPU they land on. Reachability is a hardware/topology condition, not a permission one - it needs a system with non-contiguous NUMA node IDs (the report is from POWER9 with nodes 0, 8, 252-255; check ls /sys/devices/system/node/ on non-x86 or accelerator-heavy nodes before assuming you are clear). Dense-node x86 hosts are not affected.
What to do
No fixed version is listed on this record - boot a kernel carrying the linked stable commits. Interim: audit node IDs on every architecture in the fleet and prioritise patching hosts with sparse NUMA topology; there is no configuration knob that avoids the bad index.
References
Related entries
- Linux kernel (drivers/nvme/host): The PRP list mempool is sized in the wrong units, so a large I/O that needs two PRPCVE-2022-50756 · Linux kernel (drivers/nvme/host)High
- Linux kernel (drivers/nvme/host): The NVMe/RDMA initiator destroys the queue pair before the connection manager ID, soCVE-2021-47378 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): On the NVMe/RDMA initiator, an async-event command can be submitted against an adminCVE-2022-48788 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): Same race as the RDMA variant but on NVMe/TCP, which is the far more common fabric inCVE-2022-48789 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): The multipath sibling list is walked without SRCU protection during path revalidationCVE-2022-49003 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): A discard (TRIM) request that is retried and fails again before a fresh payload isCVE-2024-41073 · Linux kernel (drivers/nvme/host)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.