Executive brief
The Linux kernel's RDMA (Remote Direct Memory Access) driver for Broadcom networking adapters contains a logic error where the firmware communication timeout handler can enter an infinite loop instead of properly reporting a failure. When firmware stops responding, the system fails to detect the timeout condition and retries indefinitely, causing the affected hardware interface to become unresponsive and potentially degrading system performance.
Technical details
The vulnerability exists in the __wait_for_resp() function within the bng_re RDMA driver (drivers/infiniband/hw/bng_re/bng_fw.c). The function is documented to return a non-zero error code when firmware commands do not complete, but the implementation ignores the timeout return value from wait_event_timeout(). When a firmware response slot remains in use after timeout and after a polled service attempt, the loop restarts and can repeat indefinitely. The fix captures the return value of wait_event_timeout(), checks if time expired (!time_left), and returns -ENODEV to signal the firmware as stalled. This allows the caller (bng_re_rcfw_send_message()) to properly mark FIRMWARE_STALL_DETECTED and return -ETIMEDOUT to command issuers. The patch requires no special privileges or network access to trigger.
Affected products
- Linux Linux kernel multiple versions (fix applied across stable branches)
Timeline
- 2026-06-25: other: Patch authored by Pengpeng Hou
- 2026-09-17: disclosed
- 2026-09-14: patched: Merged to stable kernel by Greg Kroah-Hartman