Database/Firmware, BMC & network fabric
Linux kernel RDMA/siw: out-of-bounds write from fragmented DDP/RDMAP header copies
Impact
siw is the software iWARP RDMA provider, used where RDMA verbs are needed without RoCE/InfiniBand hardware - storage clients, NVMe-oF, and RDMA test or fallback paths on GPU nodes. When an extended DDP/RDMAP header arrives split across more than one TCP callback, the second copy is sized from the full header length instead of the bytes still missing, so the copy runs past the end of the header and corrupts the receive state structure, including fpdu_part_rcvd. A later callback then uses a negative fpdu_part_rcvd as a copy offset, giving an out-of-bounds write driven by data on the wire. The input is attacker-controlled TCP segmentation against a listening siw endpoint, which makes this the rarer kind of kernel bug that is reachable remotely rather than only locally. No CVSS score, CWE or vendor advisory is attached to the record - only the stable-tree fixes.
Who can reach it
Anyone who can open a TCP connection to a siw RDMA endpoint, or who sits in the network path and controls segmentation, with no authentication at the RDMA transport layer. Only nodes that actually load the siw module and expose an iWARP listener are affected; fleets using mlx5 RoCE/InfiniBand hardware without siw are not.
What to do
Pick up the fixed stable kernel and reboot each affected node - this is kernel receive-path code, so there is no hot-patch or module-reload path that is safe while connections are live. On GPU nodes that means a drain and reboot cycle per node. If siw is not in use, unloading or blacklisting the siw module removes the exposure without a reboot. The record names no fixed version numbers beyond the stable commits.
References
Related entries
- ASPEED BMC (host-to-BMC bridges generally): The ASPEED LPC/PCIe bridge architecture exists to let the host talkNCVD-0000-001-aspeed-bmc-host-to-bmc-bridges-g · ASPEED BMC (host-to-BMC bridges generally)Unscored
- IPMI over LAN as a protocol: IPMI has no transport confidentiality guarantees worth relying on, weak session handlingNCVD-0000-002-ipmi-over-lan-as-a-protocol · IPMI over LAN as a protocolUnscored
- Internet-exposed BMC: Shodan-visible BMCs are a recurring finding at colo/neocloud buildoutsNCVD-0000-003-internet-exposed-bmc · Internet-exposed BMCUnscored
- InfiniBand subnet manager (OpenSM / UFM): The IB subnet manager has unilateral authority over LID assignment, routingNCVD-0000-004-infiniband-subnet-manager-opensm · InfiniBand subnet manager (OpenSM / UFM)Unscored
- RDMA / RoCE: RoCE and IB RDMA have no cryptographic authentication of the QP connection setup or of subsequentNCVD-0000-005-rdma-roce · RDMA / RoCEUnscored
- NVMe-oF over RDMA: NVMe-over-Fabrics inherits RDMA's lack of authenticationNCVD-0000-006-nvme-of-over-rdma · NVMe-oF over RDMAUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.