Database/Firmware, BMC & network fabric
Linux RDMA bnxt_re: destroy callbacks re-run against freed resources after a udata failure
Impact
bnxt_re zeroed its udata output only after tearing driver resources down. If the userspace copy fails, uverbs keeps the uobject and lets the destroy callback run a second time on an already-freed driver resource - a use-after-free / double-free in the Broadcom RoCE provider. A create-AH failure on the same paths leaks the hardware object instead. Exposure is limited to nodes using Broadcom NetXtreme RoCE HCAs, where any tenant holding a verbs device can drive it; the record scores it high on confidentiality, integrity and availability from a local low-privileged user.
Who can reach it
Local user with an RDMA verbs device backed by a Broadcom bnxt_re adapter; the trigger is a deliberately failing userspace copy on a destroy ioctl. No elevated privilege needed. Nodes on Mellanox/NVIDIA or Intel fabric are not affected.
What to do
Install a kernel with the bnxt_re udata-validation commits and reboot the affected nodes; ib_core and bnxt_re are pinned by running RDMA jobs, so drain first. If you have no Broadcom RoCE adapters in the fleet, no action is needed.
References
Related entries
- Linux RDMA core: integer truncation and overflow when picking a memory-region page sizeCVE-2026-97421 · Linux kernel RDMA/umem (ib_umem_find_best_pgsz boundary handling)High
- AMI MegaRAC SPx 13 (IPMI handler / host SPI flash path): The multi-tenant bare-metal nightmareCVE-2023-34335 · AMI MegaRAC SPx 13 (IPMI handler / host SPI flash path)High
- Linux kernel occ hwmon: truncated OCC poll response is parsed past the valid dataCVE-2026-68340 · Linux kernel occ hwmon driver (IBM POWER OCC poll response parser)High
- openshift-metal3 fakefish: unquoted shell variables in the Redfish shim allow command injectionCVE-2026-71567 · openshift-metal3 fakefish (Redfish-to-BMC shim scripts)High
- Arista EOS: gNMI fails to enforce Pathz policy when a group rule and a user rule cover the same pathCVE-2026-73439 · Arista EOS gNMI server (gNSI Pathz policy enforcement)High
- Intel DCI (Direct Connect Interface) UEFI setting restrictions - Xeon E3 v5/v6, Xeon Scalable, Xeon D: The UEFI settingCVE-2018-3652 · Intel DCI (Direct Connect Interface) UEFI setting restrictions - Xeon E3 v5/v6, Xeon Scalable, Xeon DHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.