Database/Firmware, BMC & network fabric
Linux kernel soft-RoCE: integer overflow in MR range check gives a remote peer out-of-bounds kernel access
Impact
A peer on the RDMA network can craft an RDMA Write/Read RETH header whose iova + length wraps past 2^64, slipping past the memory-region bounds check in mr_check_range(). The responder then computes an enormous page index - guarded only by a WARN_ON - and reads or writes outside mr->page_info, giving an out-of-bounds kernel read/write and an oops. No authentication beyond reachability of the RDMA port is needed, so on a fabric that carries traffic for more than one tenant this is remote denial of service of the node and a plausible path to kernel memory corruption. This affects the software RoCE driver (rxe), not the hardware mlx5 path: fleets that do RDMA only through ConnectX/BlueField HCAs and never load the rdma_rxe module are not exposed, while clusters that use soft-RoCE for testing, storage clients or CPU-side nodes are.
Who can reach it
Any host that can send RDMA packets to a node with the rdma_rxe module loaded and a registered memory region - typically anyone on the storage or compute fabric. No authentication, no prior queue-pair credentials beyond what a normal RoCE peer holds.
What to do
Take the stable kernel fix (five stable branches carry it; see the git.kernel.org commits) and reboot each affected node - a kernel change on the RDMA path cannot be hot-patched in place, so this is a drain-and-reboot pass across the fleet. Where soft-RoCE is not actually needed, the cheaper interim step is to confirm rdma_rxe is not loaded and blacklist it; nodes doing RDMA purely through hardware HCAs need no action. No vendor advisory beyond the kernel commits was in the record, so no single fixed release number is quoted here.
References
Related entries
- Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation): An unauthenticated HTTP GET for /PSBlock on port 49152NCVD-2014-001-supermicro-ipmi-bmc-firmware-wpc · Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation)Critical
- Dell iDRAC9 (Virtual Console / authentication): An attacker with no credentials lands directly inside the server'sCVE-2021-21538 · Dell iDRAC9 (Virtual Console / authentication)Critical
- Dell iDRAC9 (VNC server): Unauthenticated access to the iDRAC VNC consoleCVE-2022-24422 · Dell iDRAC9 (VNC server)Critical
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): The twin of CVE-2023-37293: a stack smash in the BMC'sCVE-2023-3043 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Unauthenticated code execution inside the BMC, reachedCVE-2023-37293 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
- Arista EOS (OpenConfig gNMI Set authorization): A gNMI Set request that authorization should have rejected is executedCVE-2024-27892 · Arista EOS (OpenConfig gNMI Set authorization)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.