Database/Kernel, userspace & hypervisor
Linux kernel nvmet-rdma: queue and IB resources leak when the connect backlog is exceeded
Impact
When the number of pending disconnecting queues exceeds the backlog limit, the nvmet-rdma connect path drops only the device reference and leaks the queue it just allocated along with its InfiniBand resources. Each rejected connect therefore costs the target kernel memory and HCA resources that are never returned, so a host that reconnects aggressively - or simply flapping initiators on the fabric - can grind a storage target down to allocation failures. On a GPU fleet this is the node exporting NVMe-oF over RDMA to training jobs, so the damage is felt as fabric-wide storage stalls rather than a single tenant's problem, and recovery means rebooting the box that every job is reading from. Only nodes actually running the nvmet-rdma target are exposed; initiator-only and headless compute nodes are not.
Who can reach it
Local or fabric-adjacent: anyone able to open NVMe-oF/RDMA connections to the target - typically any host on the storage fabric that is permitted to connect - can drive the leak by repeatedly connecting and disconnecting. No authentication beyond whatever the NVMe-oF subsystem's host allowlist enforces.
What to do
Update to a stable kernel carrying the nvmet-rdma connect-path fix on every node that runs the NVMe-oF RDMA target, then drain and reboot it; the nvmet module cannot be meaningfully reloaded while subsystems are exported. Interim mitigation is to tighten which hosts may connect to the target and to watch for growing slab usage on the target. No distribution-fixed version is given in the record, only the stable git commits.
References
Related entries
- AMD SEV-ES (CacheWarp): CacheWarp: INVD lets a malicious hypervisor revert SEV-ES guest memory writes, breaking guestCVE-2023-20592 · AMD SEV-ES (CacheWarp)Medium
- Linux kernel (drivers/pci): When the kernel coalesces two adjacent host-bridge apertures it invalidates the absorbedCVE-2023-53814 · Linux kernel (drivers/pci)Medium
- AMD SEV-SNP (BadRAM): BadRAM: improper validation of DIMM SPD metadata lets an attacker with physical access or ring0CVE-2024-21944 · AMD SEV-SNP (BadRAM)Medium
- OpenSSL QUIC: missing connection-level flow control lets a peer force ~100MB of heap per connectionCVE-2026-75804 · OpenSSL QUIC stack (connection-level flow control)Medium
- OpenSSL CMP client: NULL dereference when revoking a certificate by PKCS#10 CSRCVE-2026-75805 · OpenSSL CMP client (revocation-by-CSR response handling)Medium
- libuser: direct /etc/passwd rewrites can corrupt the account database and chain to local rootCVE-2015-3246 · libuser / usermode userhelper (/etc/passwd modification on RHEL)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.