Database/Kernel, userspace & hypervisor
Linux kernel RDMA/rxe: ODP write paths accept read-only pages, letting RDMA traffic overwrite the page cache
Impact
rxe_check_pagefault() lost its access-permission test and only checked HMM_PFN_VALID, so a page faulted in read-only satisfies the check and ODP write operations (RDMA WRITE, RDMA READ response, SEND payload, atomics) modify it through kmap without ever breaking copy-on-write. Per the commit message, an unprivileged local user can register an ODP memory region over a PROT_READ file mapping and have incoming RDMA traffic overwrite the page cache of a file it holds only O_RDONLY - including /etc/passwd or a setuid binary. The report puts this in the same primitive class as Dirty COW. On a GPU node that exposes soft-RoCE to tenant workloads, that is a local-user-to-root path on a shared host, and the corruption lands in the page cache where other tenants' processes read it.
Who can reach it
Local user on the host with access to the rdma uverbs devices (no special privilege beyond that) who can register an ODP memory region and drive RDMA traffic at it. Only affects the software RoCE driver (rxe); mlx5 hardware ODP already enforced the HMM_PFN_WRITE invariant.
What to do
Take the stable kernel fix (three stable commits are listed) and reboot each affected node - there is no module-level mitigation short of not loading rxe. Where soft-RoCE is not actually needed, blacklisting the rxe module removes the exposure without a reboot window of its own. The advisory names no single fixed release; match the commit to the stable branch you run.
References
Related entries
- Linux kernel RDMA/rxe: MR re-registration swaps the PD before validating access flags, freeing a live PDCVE-2026-98366 · Linux kernel RDMA/rxe rxe_rereg_user_mr() (access-flag validation ordering)High
- Linux kernel RDMA/siw: failed QP modify in siw_accept() races QP-to-ERROR transition into a use-after-freeCVE-2026-98367 · Linux kernel RDMA/siw siw_accept() (CEP association cleared outside state_lock)High
- Linux kernel virtio-gpu: unvalidated EDID block offset lets a malicious backend read past a kernel bufferCVE-2026-68255 · Linux kernel drm/virtio (virtio_get_edid_block response bounds)High
- Linux kernel (drivers/pci): The option-ROM parser trusts the header and data-structure offsets it reads out of theCVE-2026-72487 · Linux kernel (drivers/pci)High
- Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough): Buffer overflow on the MSI-X table write pathCVE-2015-8554 · Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough)High
- Linux kernel RDS net/rds/recv.c - rds_inc_info_copy: A structure member is left uninitialised before the RDS messageCVE-2016-5244 · Linux kernel RDS net/rds/recv.c - rds_inc_info_copyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.