Database/Firmware, BMC & network fabric
Linux RDMA/rtrs-srv: unvalidated usr_len from the wire underflows data_len into an out-of-bounds length
Impact
usr_len comes straight off the wire (le16_to_cpu) and is used to compute data_len = off - usr_len with no check that usr_len <= off. A client that sends usr_len > off wraps data_len to a huge size_t, which is handed to the rdma_ev callback as a memory length and drives an out-of-bounds access in the server. This is a remote, pre-auth memory-corruption primitive against any node running the RTRS transport server - typically the storage side of an RNBD/RTRS block-over-RDMA setup on an InfiniBand or RoCE fabric that also carries tenant traffic. A crash takes the storage target down for every client attached to it; worse outcomes are plausible given the attacker controls the length.
Who can reach it
Any host that can open an RTRS session to the server over the RDMA fabric. No authentication. Only affects nodes with the rtrs-srv module in use.
What to do
Apply the stable-kernel fix (three stable branches carry it) and reboot the affected storage/target nodes. If you do not run RTRS/RNBD, confirm the module is not loaded and there is nothing to do. Restricting which hosts can reach the RTRS listener on the fabric is a partial mitigation while you schedule the reboot.
References
Related entries
- Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation): An unauthenticated HTTP GET for /PSBlock on port 49152NCVD-2014-001-supermicro-ipmi-bmc-firmware-wpc · Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation)Critical
- Dell iDRAC9 (Virtual Console / authentication): An attacker with no credentials lands directly inside the server'sCVE-2021-21538 · Dell iDRAC9 (Virtual Console / authentication)Critical
- Dell iDRAC9 (VNC server): Unauthenticated access to the iDRAC VNC consoleCVE-2022-24422 · Dell iDRAC9 (VNC server)Critical
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): The twin of CVE-2023-37293: a stack smash in the BMC'sCVE-2023-3043 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Unauthenticated code execution inside the BMC, reachedCVE-2023-37293 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
- Arista EOS (OpenConfig gNMI Set authorization): A gNMI Set request that authorization should have rejected is executedCVE-2024-27892 · Arista EOS (OpenConfig gNMI Set authorization)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.