Back

HIGH

RDMA/rxe: Fix responder length checking for UD request packets

Published Jul 12, 2024

Description

According to the IBA specification: If a UD request packet is detected with an invalid length, the request shall be an invalid request and it shall be silently dropped by the responder. The responder then waits for a new request packet.

commit 689c5421bfe0 ("RDMA/rxe: Fix incorrect responder length checking") defers responder length check for UD QPs in function `copy_data`. But it introduces a regression issue for UD QPs.

When the packet size is too large to fit in the receive buffer. `copy_data` will return error code -EINVAL. Then `send_data_in` will return RESPST_ERR_MALFORMED_WQE. UD QP will transfer into ERROR state.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jul 12, 2024
Updated Aug 5, 2026
Reserved Jul 12, 2024
CISA Vulnrichment
Updated Sep 10, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Low
Public date Jul 12, 2024
ENISA EUVD
Assigner Linux
Published Jul 12, 2024
Updated Aug 5, 2026
Exploited since n/a
EUVD-2024-38787