Executive brief
The Broadcom NetXtreme RoCE (RDMA over Converged Ethernet) driver in the Linux kernel contains a race condition when destroying queue pairs used for high-speed network communication. When a queue pair is destroyed while completion queue handlers are still running, the driver may attempt to process events on an already-freed completion queue, causing a kernel panic and system crash. This affects systems using Broadcom network adapters for RDMA workloads.
Technical details
The vulnerability is a race condition (CWE-362) in the RDMA/bnxt_re driver's queue pair destruction path. The root cause is that completion handlers (poll_cq) can be scheduled by the notification queue (NQ) while the QP destroy operation is still in progress, since completion queues remain active during QP destruction. This allows destroy_cq and poll_cq to execute concurrently, leading to use-after-free when polling an already-freed completion queue. The fix involves synchronizing all pending notification queue entries before returning from destroy_qp, ensuring no further completion handlers are scheduled. No user interaction or authentication is required; the vulnerability can be triggered locally by drivers performing QP lifecycle operations. The patch was released in Linux kernel version 5.15+ and backported to stable branches.
Affected products
- Linux Linux Kernel Affected versions in RDMA/bnxt_re driver; patched in 5.15+ and stable backports
Timeline
- 2023-07-14: disclosed: Patch submitted by Kashyap Desai
- 2023-07-17: patched: Upstream commit b5bbc6551297447d3cca55cf907079e206e9cd82 merged
- 2023-08-03: patched: Backported to stable kernel branches by Greg Kroah-Hartman