Database/Kernel, userspace & hypervisor
Linux kernel nvme-rdma: double cleanup and DMA unmap after request completion on the -EIO path
Impact
On the -EIO path in the NVMe-over-RDMA submission routine, the host path error helper completes the request and the code then still cleans up the command and unmaps the SQE DMA - a use-after-completion with a DMA unmap on an already-completed request. This reaches GPU nodes that mount NVMe-oF over RDMA for datasets and checkpoints, which is common where the fabric is InfiniBand or RoCE. Triggering it needs the error path to be hit, so the realistic route is fabric instability or a misbehaving target rather than a tenant action; the likely outcome is a host crash and the loss of every job on the node.
Who can reach it
Not a tenant-facing path. Requires the nvme-rdma error path to fire, which follows from storage fabric or target-side faults; anyone who can disrupt the storage fabric or control an NVMe-oF target the host connects to is in a position to provoke it.
What to do
Apply the stable kernel fix and reboot each affected node. Only hosts that actually use NVMe over RDMA are affected - if your GPU nodes mount storage another way, this can ride along with the next scheduled kernel window rather than driving one.
References
Related entries
- Xen through 4.12.x - passed-through PCI devices left able to DMA into host memory after being handed to an untrustedCVE-2019-18424 · Xen through 4.12.x - passed-through PCI devices left able to DMA into host memory after being handed to an untrusted…Medium
- Xen on AMD-Vi (AMD IOMMU) - ACPI IVMD unity-map page permissions: Xen honours ACPI-described IOMMU unity mappings butCVE-2021-28694 · Xen on AMD-Vi (AMD IOMMU) - ACPI IVMD unity-map page permissionsMedium
- Xen on AMD-Vi - IOMMU page mapping permissions: Second of the XSA-378 IOMMU page-mapping issues on AMD-Vi. IncorrectCVE-2021-28695 · Xen on AMD-Vi - IOMMU page mapping permissionsMedium
- Xen on AMD-Vi - IOMMU page mapping permissions: Third of the XSA-378 AMD-Vi mapping issues. Same practical consequenceCVE-2021-28696 · Xen on AMD-Vi - IOMMU page mapping permissionsMedium
- Linux kernel (arch/x86/kvm): A failed RSM leaves the vCPU's SMM flag and the MMU role out of sync, so KVM resolves aCVE-2021-47230 · Linux kernel (arch/x86/kvm)Medium
- VMware ESXi: AD-integrated ESXi grants full host admin to any member of a re-created "ESX Admins" groupCVE-2024-37085 · VMware ESXiMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.