Executive brief
The Linux kernel's RDMA bnxt_re driver for Broadcom network adapters had an incorrect device cleanup sequence that could lead to use-after-free memory corruption. When a device is removed, memory could be accessed after it was freed, potentially allowing a privileged local attacker to crash the system or execute code with kernel privileges.
Technical details
A use-after-free (UAF) vulnerability exists in the RDMA/bnxt_re driver's device removal function due to improper ordering of cleanup operations. The vulnerable code called ib_dealloc_device() before bnxt_re_dev_uninit(), freeing the InfiniBand device structure while references to it still existed during cleanup. An attacker with local access and privileges to trigger device removal or hot-unplug operations could exploit this to cause kernel memory corruption. The fix reorders the cleanup sequence to ensure ib_dealloc_device() is called only after all device-specific cleanup is complete. This is a kernel-level vulnerability requiring local access; no user interaction is needed once device removal is triggered.
Affected products
- Linux Linux Kernel 5.0 through 6.18 and other stable branches (fixed via commit 5363fc488da579923edf6a2fdca3d3b651dd800b)
Timeline
- 2023-08-10: disclosed: Patch merged into Linux kernel mainline
- 2023-08-16: patched: Backported to stable kernel trees