{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-57936",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-01-19T11:50:08.377Z",
        "datePublished": "2025-01-21T12:01:31.907Z",
        "dateUpdated": "2026-08-05T11:46:59.812Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:46:59.812Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Fix max SGEs for the Work Request\n\nGen P7 supports up to 13 SGEs for now. WQE software structure\ncan hold only 6 now. Since the max send sge is reported as\n13, the stack can give requests up to 13 SGEs. This is causing\ntraffic failures and system crashes.\n\nUse the define for max SGE supported for variable size. This\nwill work for both static and variable WQEs."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:N - Kernel RDMA target ULPs (nvmet-rdma, NFS/RDMA server via svcrdma, iSER/SRP) build work requests through `rdma_rw_init_map_wrs()` with up to 13 SGEs — bnxt_re does not set `max_sgl_rd`, so the multi-SGE (non-MR) path is always taken on RoCE — meaning a remote initiator's ordinary I/O with ≥7 scatterlist entries drives the overflow on the server over routable RoCEv2 (UDP/4791). The same code is also reachable locally via world-readable `/dev/infiniband/uverbs*`.\nAC:L - There is no race and no dependence on memory layout the attacker cannot influence — creating a QP with `cap.max_send_sge > 6` (or simply issuing a multi-segment I/O against an RDMA target) and posting one work request deterministically overruns the 6-entry stack array every time.\nPR:N - On the remote path an NVMe-oF/RDMA or NFS/RDMA client needs no privileges on the target host and nvmet accepts connections with no cryptographic authentication by default, so the >6-SGE work request is built by the victim kernel purely in response to unauthenticated peer I/O.\nUI:N - No victim action is required; the malicious work request is processed automatically by the target's RDMA queue-pair handling or by the attacker's own `ib_uverbs_post_send()` call.\nS:U - The out-of-bounds stack write, the wild `pbl_ptr[]` write and the resulting corruption all occur within the kernel's own security authority, with no hypervisor or IOMMU boundary being crossed.\nC:H - The clobbered `wqe.num_sge` makes `bnxt_qplib_put_sges()` read up to ~1 MB past the 272-byte stack object and copy that kernel stack content into the DMA-visible send queue for the NIC to consume, and the write primitive additionally supports arbitrary kernel memory disclosure.\nI:H - `bnxt_re_build_sgl()` writes fully attacker-controlled 64-bit values past a 96-byte on-stack array — unbounded in the VARIABLE-mode user-QP path where `sq->max_sge` is never clamped — smashing the stack canary, saved registers and return addresses, a classic control-flow-hijack primitive.\nA:H - The commit itself states the condition causes \"traffic failures and system crashes\"; the out-of-bounds stack access and the wild pointer write through the unbounded hardware-queue index reliably oops or panic the kernel."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/infiniband/hw/bnxt_re/qplib_fp.h"
                    ],
                    "versions": [
                        {
                            "version": "36e1b6890f228ccfc867031ecedffe50958b25e4",
                            "lessThan": "3de1b50f055dc2ca7072a526cdda21f691c22dd9",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "227f51743b61fe3f6fc481f0fb8086bf8c49b8c9",
                            "lessThan": "9a479088e0c8f6140b8c7752b563bc8c6c6dcc8c",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "227f51743b61fe3f6fc481f0fb8086bf8c49b8c9",
                            "lessThan": "79d330fbdffd8cee06d8bdf38d82cb62d8363a27",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/infiniband/hw/bnxt_re/qplib_fp.h"
                    ],
                    "versions": [
                        {
                            "version": "6.12",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.12",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.9",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.13",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12",
                                    "versionEndExcluding": "6.12.9"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12",
                                    "versionEndExcluding": "6.13"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/3de1b50f055dc2ca7072a526cdda21f691c22dd9"
                },
                {
                    "url": "https://git.kernel.org/stable/c/9a479088e0c8f6140b8c7752b563bc8c6c6dcc8c"
                },
                {
                    "url": "https://git.kernel.org/stable/c/79d330fbdffd8cee06d8bdf38d82cb62d8363a27"
                }
            ],
            "title": "RDMA/bnxt_re: Fix max SGEs for the Work Request",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}