GPU VulnDB

Database/Firmware, BMC & network fabric

Linux RDMA core: integer truncation and overflow when picking a memory-region page size

CVSS 7.8CVE-2026-97421Firmware, BMC & network fabriccurated

Impact

ib_umem_find_best_pgsz() took the IOVA in a narrower type than the u64 it is stored in, did not check the length against the IOVA, and overflowed its GENMASK for registrations larger than 4G. The result is a wrong page-size selection for a user-registered memory region, meaning the HCA can be programmed to address memory outside the region the user pinned. This is the RDMA verbs path every InfiniBand and RoCE workload uses, so on a GPU node it is reachable by any tenant that can register memory for NCCL or MPI traffic. The upstream note flags 32-bit builds as most exposed; on 64-bit hosts the >4G length overflow is the case that still applies.

Who can reach it

Local user with an RDMA device (/dev/infiniband/uverbs*) - any tenant permitted to run GPUDirect, NCCL or MPI jobs on the fabric. No authentication beyond having the verbs device; not remotely triggerable over the wire by itself.

What to do

Install a kernel carrying the RDMA/umem fix and reboot each affected node; the ib_core and provider modules are in use by every running RDMA job, so this is a drain-and-reboot, not a module reload. No standalone mitigation other than removing verbs access from untrusted tenants.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.