mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [BUG] RDMA/rxe: user QP can submit kernel-only REG_MR opcode
@ 2026-10-06  9:13 sungbyeongchan
  0 siblings, 0 replies; only message in thread
From: sungbyeongchan @ 2026-10-06  9:13 UTC (permalink / raw)
  To: Zhu Yanjun, Jason Gunthorpe, Leon Romanovsky
  Cc: linux-rdma, linux-kernel, security

Hello,

I found a raw kernel-pointer dereference reachable from an RXE user
send queue.

RXE user QPs expose their send queues through mmap.  A userspace client
can publish opcode IB_WR_REG_MR even though that opcode and its struct
ib_mr pointer are kernel-only.  The RXE opcode table enables the local
operation on RC QPs, and rxe_do_local_ops() passes the shared WQE to
rxe_reg_fast_mr().  The latter interprets reserved userspace union bytes
as a struct ib_mr pointer without a handle lookup or acquired reference.

I reproduced this twice on commit
ff47652a4b66c067c765a7ad464d930b5a9367cc.  An unprivileged uid/gid
65534 client published IB_WR_REG_MR with zero pointer bytes in its mapped
SQ.  Both runs produced a fatal fault in rxe_reg_fast_mr() and a kernel
panic.  A control using IB_WR_LOCAL_INV traversed the same local-operation
dispatcher without a sanitizer report or oops.

The demonstrated impact is a deterministic unprivileged denial of
service through a raw-pointer type confusion.  Although the source has
conditional MR field writes after several checks, I did not reach those
writes and do not claim arbitrary write, information disclosure, code
execution, or privilege escalation.

I tested rejecting IB_WR_REG_MR on user QPs before rxe_reg_fast_mr() is
called.  Kernel QPs retain the existing path.  The malicious case and
normal control were both clean after the change, and fixed A/B testing
passed.

I performed a best-effort public duplicate search through 2026-10-06
and found no exact public report for submission of kernel-only REG_MR
through an RXE user-mapped SQ.

This report was prepared with AI assistance and is being treated as
public under Documentation/process/security-bugs.rst.  A tested source
reproducer, logs, configuration, and proposed patch are available to the
maintainers on request; the reproducer is intentionally not attached to
this public report.

Assisted-by: LLM

Regards,
sungbyeongchan


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-10-06  9:23 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06  9:13 [BUG] RDMA/rxe: user QP can submit kernel-only REG_MR opcode sungbyeongchan

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®