Database/Firmware, BMC & network fabric
Linux kernel - SRP target (srpt), drivers/infiniband/ulp/srpt/ib_srpt.c: An integer overflow in the immediate-data
Impact
An integer overflow in the immediate-data length check on the SRP target lets a remote initiator bypass the bound and reach kernel memory it should not. The srpt target serves block storage over InfiniBand to compute clients, so a single tenant that can connect as an initiator gets kernel-level compromise of the storage node - and through it, access to every other tenant's volumes exported from the same target.
Who can reach it
A remote SRP initiator submits a command whose immediate data length is chosen so the length arithmetic wraps, defeating the check. Any host allowed to connect to the target can do it; on fabrics without per-tenant partitioning that is any host on the subnet.
What to do
Host reboot / kernel upgrade on SRP target nodes. Interim: enforce InfiniBand partitioning so only authorised initiators can reach the target port (SM config change, effective on the next sweep, no reload), and restrict target ACLs to known initiator GUIDs. Where SRP has been superseded by NVMe-oF, decommission the srpt target and unload the module - the cleanest fix.
References
Related entries
- Cisco Catalyst SD-WAN Manager: URI-encoding auth bypass gives unauthenticated admin API accessCVE-2026-76504 · Cisco Catalyst SD-WAN Manager (API session authentication, URI encoding handling)Critical
- FreeIPMI SEL parser: stack overflow on malformed Fujitsu iRMC long-text SEL responsesCVE-2026-85504 · FreeIPMI libfreeipmi SEL parser (Fujitsu iRMC OEM long-text records)Critical
- FreeIPMI ipmi-oem: stack overflow parsing Dell get-system-info responses returned by a BMCCVE-2026-85506 · FreeIPMI ipmi-oem (Dell get-system-info handlers)Critical
- FreeIPMI FRU reader: stack overflow when a BMC returns more FRU bytes than requestedCVE-2026-85509 · FreeIPMI libfreeipmi FRU reader (_read_fru_data)Critical
- Linux RDMA/rtrs-srv: unvalidated usr_len from the wire underflows data_len into an out-of-bounds lengthCVE-2026-97413 · Linux kernel RDMA/rtrs-srv (process_read/process_write usr_len validation)Critical
- Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation): An unauthenticated HTTP GET for /PSBlock on port 49152NCVD-2014-001-supermicro-ipmi-bmc-firmware-wpc · Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.