Database/Kernel, userspace & hypervisor
Linux kernel RDMA/siw: failed QP modify in siw_accept() races QP-to-ERROR transition into a use-after-free
Impact
When siw_qp_modify() fails inside siw_accept(), the QP's state_lock is dropped before the error-path cleanup runs. A concurrent ibv_modify_qp() moving the QP to ERROR can slip into that window, put the connection endpoint and NULL qp->cep, after which siw_accept()'s error path writes through the freed cep. The result is kernel memory corruption driven from unprivileged userspace on any host running the software iWARP driver. On a multi-tenant GPU node this is a local escalation and crash primitive in a driver most operators do not realise is loaded; the fix clears qp->cep and drops the association reference while still holding the write lock.
Who can reach it
Local user with access to the RDMA uverbs devices, racing a connection accept against a QP state change. Requires the siw driver to be loaded; not remotely triggerable on its own.
What to do
Pick up the stable kernel fix (five stable commits listed) and reboot each node. Hosts that do not need software iWARP can blacklist or unload the siw module instead, which removes the attack surface without waiting for a kernel rollout. The record names no fixed release version.
References
Related entries
- Linux kernel virtio-gpu: unvalidated EDID block offset lets a malicious backend read past a kernel bufferCVE-2026-68255 · Linux kernel drm/virtio (virtio_get_edid_block response bounds)High
- Linux kernel (drivers/pci): The option-ROM parser trusts the header and data-structure offsets it reads out of theCVE-2026-72487 · Linux kernel (drivers/pci)High
- Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough): Buffer overflow on the MSI-X table write pathCVE-2015-8554 · Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough)High
- Linux kernel RDS net/rds/recv.c - rds_inc_info_copy: A structure member is left uninitialised before the RDS messageCVE-2016-5244 · Linux kernel RDS net/rds/recv.c - rds_inc_info_copyHigh
- QEMU (virtio-net): Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU processCVE-2021-3748 · QEMU (virtio-net)High
- Linux kernel (drivers/nvme/target): When the target's peer-to-peer memory pool runs dry, it still tries to return theCVE-2021-47130 · Linux kernel (drivers/nvme/target)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.