CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's RDMA/rxe component, specifically in the handling of non-SRQ (Shared Receive Queue) Queue Pairs (QPs). A malicious user can exploit this flaw to manipulate WQE fields, potentially leading to out-of-bounds reads during processing, which could compromise system integrity. Organizations utilizing Linux systems with RDMA capabilities should prioritize patching to mitigate this risk.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path For non-SRQ QPs, the responder reads WQE fields directly from the shared queue buffer mapped into userspace. This allows a malicious user to modify fields like num_sge or sge entries while the kernel is processing the WQE, leading to out-of-bounds reads in rxe_resp_check_length() and copy_data(). Introduce get_recv_wqe() that validates num_sge and copies the WQE to a kernel-local buffer before processing, matching the approach already used for SRQ WQEs in get_srq_wqe(). The srq_wqe buffer is reused since SRQ and non-SRQ paths are mutually exclusive per QP.