Database/Firmware, BMC & network fabric
Linux RDMA core: integer truncation and overflow when picking a memory-region page size
Impact
ib_umem_find_best_pgsz() took the IOVA in a narrower type than the u64 it is stored in, did not check the length against the IOVA, and overflowed its GENMASK for registrations larger than 4G. The result is a wrong page-size selection for a user-registered memory region, meaning the HCA can be programmed to address memory outside the region the user pinned. This is the RDMA verbs path every InfiniBand and RoCE workload uses, so on a GPU node it is reachable by any tenant that can register memory for NCCL or MPI traffic. The upstream note flags 32-bit builds as most exposed; on 64-bit hosts the >4G length overflow is the case that still applies.
Who can reach it
Local user with an RDMA device (/dev/infiniband/uverbs*) - any tenant permitted to run GPUDirect, NCCL or MPI jobs on the fabric. No authentication beyond having the verbs device; not remotely triggerable over the wire by itself.
What to do
Install a kernel carrying the RDMA/umem fix and reboot each affected node; the ib_core and provider modules are in use by every running RDMA job, so this is a drain-and-reboot, not a module reload. No standalone mitigation other than removing verbs access from untrusted tenants.
References
Related entries
- AMI MegaRAC SPx 13 (IPMI handler / host SPI flash path): The multi-tenant bare-metal nightmareCVE-2023-34335 · AMI MegaRAC SPx 13 (IPMI handler / host SPI flash path)High
- Linux kernel occ hwmon: truncated OCC poll response is parsed past the valid dataCVE-2026-68340 · Linux kernel occ hwmon driver (IBM POWER OCC poll response parser)High
- openshift-metal3 fakefish: unquoted shell variables in the Redfish shim allow command injectionCVE-2026-71567 · openshift-metal3 fakefish (Redfish-to-BMC shim scripts)High
- Arista EOS: gNMI fails to enforce Pathz policy when a group rule and a user rule cover the same pathCVE-2026-73439 · Arista EOS gNMI server (gNSI Pathz policy enforcement)High
- Intel DCI (Direct Connect Interface) UEFI setting restrictions - Xeon E3 v5/v6, Xeon Scalable, Xeon D: The UEFI settingCVE-2018-3652 · Intel DCI (Direct Connect Interface) UEFI setting restrictions - Xeon E3 v5/v6, Xeon Scalable, Xeon DHigh
- AMI MegaRAC SPx (BMC cryptography / HMAC): The BMC uses inadequate HMAC strength, so an attacker positionedCVE-2023-34337 · AMI MegaRAC SPx (BMC cryptography / HMAC)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.