Executive brief
A vulnerability in the Linux kernel's InfiniBand (IB) subsystem could allow a local user to cause a system crash. The issue occurs when the system attempts to perform diagnostic tracing while handling network management packets. This can lead to an unstable system state or a complete kernel panic, impacting service availability.
Technical details
A bug in the IB/mad component of the Linux kernel arises from calling ib_query_pkey() within an atomic context during tracepoint execution (specifically in ib_mad_recv_done and create_mad_addr_info). Tracepoints are not permitted to sleep, but ib_query_pkey() may trigger a sleep, leading to a kernel 'splat' or warning in rb_commit. A local attacker could potentially trigger this condition to cause a Denial of Service (DoS) via a kernel panic. The fix involves removing the problematic ib_query_pkey() calls from the tracepoint handlers.
Affected products
- Linux Linux Kernel 5.2 to 5.15.86, 5.16 to 6.0.16, 6.1 to 6.1.2
Timeline
- 2022-11-10: patched: Mainline patch committed
- 2025-10-04: disclosed: CVE published
References
- https://git.kernel.org/stable/c/47e31b86edff36f2d26cbc88ce695d98ff804178
- https://git.kernel.org/stable/c/5c20311d76cbaeb7ed2ecf9c8b8322f8fc4a7ae3
- https://git.kernel.org/stable/c/cea70a572c0cb9728d728cfebe7d5bd485e97513
- https://git.kernel.org/stable/c/d45e6ccb8e98d8339631f32984d345a663e74ce2
- https://git.kernel.org/stable/c/fa8a2f3be78e4585996bcf4c15e4504441a4c7a0