Database/Firmware, BMC & network fabric
Linux kernel bnxt_re: uninitialised shared page mapped to userspace leaks kernel memory
Impact
bnxt_re_alloc_ucontext() allocates the per-context shared page with __get_free_page() and no __GFP_ZERO, then maps it into userspace via vm_insert_page(). The driver writes only 4 bytes into it, so the remaining 4092 bytes are whatever kernel object last freed that page - handed straight to the process that opened the verbs device. On a node where tenants get direct RDMA access for RoCE traffic, that is an unprivileged read of stale kernel heap contents, useful for leaking pointers and defeating KASLR before a second bug. The leak is per-context and repeatable, so an attacker can allocate contexts in a loop and sample many freed pages.
Who can reach it
Local user on a host with a Broadcom bnxt_re RDMA device who can open /dev/infiniband/uverbsX - typically rdma group membership, or any container given the verbs device node. No privileged capability needed beyond that device access: GET_CONTEXT followed by a single mmap() at pgoff 0.
What to do
Fix is a one-line switch to get_zeroed_page(), backported across five stable branches (see the git.kernel.org commits). Install the patched kernel and reboot the node; there is no runtime knob. Until then, the only mitigation is to stop exposing /dev/infiniband/uverbs* to untrusted tenants on bnxt_re hosts, which for RoCE-attached GPU nodes usually means losing user-space RDMA.
References
Related entries
- Linux kernel PMBus hwmon: type confusion in the alert path reads past the attribute allocationCVE-2026-74711 · Linux kernel hwmon pmbus core (pmbus_notify attribute type confusion)Unscored
- Linux kernel hns_roce: bonding teardown order leaks resources and leaves a stale netdev notifierCVE-2026-80625 · Linux kernel hns_roce (RoCE bonding resource teardown order)Unscored
- Linux kernel Soft-RoCE: modify_qp frees the rd_atomic array using the new size, writing out of boundsCVE-2026-80863 · Linux kernel RDMA/rxe (free_rd_atomic_resources during modify_qp)Unscored
- Linux kernel rdma_rxe: use-after-free in the responder task when modify_qp swaps the RD-atomic resource arrayCVE-2026-80864 · Linux kernel Soft-RoCE responder (rdma_rxe, IB_QP_MAX_DEST_RD_ATOMIC modify_qp)Unscored
- Linux kernel mlx5_ib: implicit ODP parent mkey re-registered in place, racing its child mkeys and mr->pdCVE-2026-80880 · Linux kernel mlx5_ib implicit ODP (rereg_mr on a parent mkey)Unscored
- Linux tpm_i2c_nuvoton: unbalanced enable_irq() on wait timeout can wedge TPM accessCVE-2026-80930 · Linux kernel tpm_i2c_nuvoton (TPM I2C driver IRQ balance)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.