CVE-2024-57936 (GCVE-0-2024-57936)
Vulnerability from cvelistv5
Published
2025-01-21 12:01
Modified
2026-08-05 11:46
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix max SGEs for the Work Request Gen P7 supports up to 13 SGEs for now. WQE software structure can hold only 6 now. Since the max send sge is reported as 13, the stack can give requests up to 13 SGEs. This is causing traffic failures and system crashes. Use the define for max SGE supported for variable size. This will work for both static and variable WQEs.
Impacted products
Vendor Product Version
Linux Linux Version: 36e1b6890f228ccfc867031ecedffe50958b25e4
Version: 227f51743b61fe3f6fc481f0fb8086bf8c49b8c9
Version: 227f51743b61fe3f6fc481f0fb8086bf8c49b8c9
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/hw/bnxt_re/qplib_fp.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "3de1b50f055dc2ca7072a526cdda21f691c22dd9",
              "status": "affected",
              "version": "36e1b6890f228ccfc867031ecedffe50958b25e4",
              "versionType": "git"
            },
            {
              "lessThan": "9a479088e0c8f6140b8c7752b563bc8c6c6dcc8c",
              "status": "affected",
              "version": "227f51743b61fe3f6fc481f0fb8086bf8c49b8c9",
              "versionType": "git"
            },
            {
              "lessThan": "79d330fbdffd8cee06d8bdf38d82cb62d8363a27",
              "status": "affected",
              "version": "227f51743b61fe3f6fc481f0fb8086bf8c49b8c9",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/hw/bnxt_re/qplib_fp.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "lessThan": "6.12",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.9",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.13",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.9",
                  "versionStartIncluding": "6.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13",
                  "versionStartIncluding": "6.12",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Fix max SGEs for the Work Request\n\nGen P7 supports up to 13 SGEs for now. WQE software structure\ncan hold only 6 now. Since the max send sge is reported as\n13, the stack can give requests up to 13 SGEs. This is causing\ntraffic failures and system crashes.\n\nUse the define for max SGE supported for variable size. This\nwill work for both static and variable WQEs."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - Kernel RDMA target ULPs (nvmet-rdma, NFS/RDMA server via svcrdma, iSER/SRP) build work requests through `rdma_rw_init_map_wrs()` with up to 13 SGEs \u2014 bnxt_re does not set `max_sgl_rd`, so the multi-SGE (non-MR) path is always taken on RoCE \u2014 meaning a remote initiator\u0027s ordinary I/O with \u22657 scatterlist entries drives the overflow on the server over routable RoCEv2 (UDP/4791). The same code is also reachable locally via world-readable `/dev/infiniband/uverbs*`.\nAC:L - There is no race and no dependence on memory layout the attacker cannot influence \u2014 creating a QP with `cap.max_send_sge \u003e 6` (or simply issuing a multi-segment I/O against an RDMA target) and posting one work request deterministically overruns the 6-entry stack array every time.\nPR:N - On the remote path an NVMe-oF/RDMA or NFS/RDMA client needs no privileges on the target host and nvmet accepts connections with no cryptographic authentication by default, so the \u003e6-SGE work request is built by the victim kernel purely in response to unauthenticated peer I/O.\nUI:N - No victim action is required; the malicious work request is processed automatically by the target\u0027s RDMA queue-pair handling or by the attacker\u0027s own `ib_uverbs_post_send()` call.\nS:U - The out-of-bounds stack write, the wild `pbl_ptr[]` write and the resulting corruption all occur within the kernel\u0027s own security authority, with no hypervisor or IOMMU boundary being crossed.\nC:H - The clobbered `wqe.num_sge` makes `bnxt_qplib_put_sges()` read up to ~1 MB past the 272-byte stack object and copy that kernel stack content into the DMA-visible send queue for the NIC to consume, and the write primitive additionally supports arbitrary kernel memory disclosure.\nI:H - `bnxt_re_build_sgl()` writes fully attacker-controlled 64-bit values past a 96-byte on-stack array \u2014 unbounded in the VARIABLE-mode user-QP path where `sq-\u003emax_sge` is never clamped \u2014 smashing the stack canary, saved registers and return addresses, a classic control-flow-hijack primitive.\nA:H - The commit itself states the condition causes \"traffic failures and system crashes\"; the out-of-bounds stack access and the wild pointer write through the unbounded hardware-queue index reliably oops or panic the kernel."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:46:59.812Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3de1b50f055dc2ca7072a526cdda21f691c22dd9"
        },
        {
          "url": "https://git.kernel.org/stable/c/9a479088e0c8f6140b8c7752b563bc8c6c6dcc8c"
        },
        {
          "url": "https://git.kernel.org/stable/c/79d330fbdffd8cee06d8bdf38d82cb62d8363a27"
        }
      ],
      "title": "RDMA/bnxt_re: Fix max SGEs for the Work Request",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-57936",
    "datePublished": "2025-01-21T12:01:31.907Z",
    "dateReserved": "2025-01-19T11:50:08.377Z",
    "dateUpdated": "2026-08-05T11:46:59.812Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…