Database/Firmware, BMC & network fabric
Linux kernel RDMA/rxe: use-after-free on multicast group when rxe_mcast_add() fails
Impact
rxe_get_mcg() published a newly allocated multicast group in rxe->mcg_tree before programming the backing Ethernet multicast address. If rxe_mcast_add() then failed - for example -ENODEV when the backing netdev has been removed, or a propagated dev_mc_add() error - the unwind freed the group without removing it from the tree, and the next lookup of the same MGID dereferenced freed memory. The fix was validated under KASAN with the error return forced. This is the software RoCE provider, not a ConnectX or other hardware HCA, so it only matters on nodes that actually load rxe - test rigs, nodes without an RDMA-capable NIC, or containers that fall back to soft-RoCE. Where it is loaded, a local RDMA client reaches the path with ATTACH_MCAST on a UD QP, which makes a kernel-memory corruption primitive available to an unprivileged tenant process that holds an RDMA device.
Who can reach it
Local userspace RDMA client issuing ATTACH_MCAST on a UD QP against an rxe device; no elevated privilege beyond access to the RDMA device. Requires the rxe_mcast_add() error path to be reached, which the record describes as needing an error such as netdev removal. Not reachable from the network.
What to do
Apply the stable kernel commits in the record and reboot each affected node. If rxe is not required, the cheaper mitigation is to not load it: blacklist the rdma_rxe module and confirm it is absent from running nodes, which removes the exposure without a kernel update. Nodes using hardware RDMA (mlx5, irdma, bnxt_re) are unaffected by this path.
References
Related entries
- GRUB2 (USB device initialization): Out-of-bounds write in grub_usb_device_initialize from a malicious USB descriptorCVE-2020-25647 · GRUB2 (USB device initialization)Medium
- AMD Secure Processor PCI driver - input validation: Improper input validation in the ASP PCI driver lets a localCVE-2025-0045 · AMD Secure Processor PCI driver - input validationMedium
- AMD SEV firmware - RMP write during SNP initialization: A privileged attacker can write to the reverse map page duringCVE-2025-29939 · AMD SEV firmware - RMP write during SNP initializationMedium
- AMD Secure Processor PCI driver - use-after-free: A use-after-free reachable through the ASP PCI driverCVE-2025-48521 · AMD Secure Processor PCI driver - use-after-freeMedium
- IBM Power Systems FSP: authenticated admin can force a persistent degraded operating modeCVE-2026-16938 · IBM Power Systems Firmware (FSP privileged system configuration controls)Medium
- Arista EOS: crafted password creates orphan sessions until logins are exhaustedCVE-2026-19641 · Arista EOS password authentication (session handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.