GPU VulnDB

Database/Firmware, BMC & network fabric

Linux bnxt_re RoCE driver (bnxt_re_copy_err_stats out-of-bounds write): Out-of-bounds write in the Broadcom RoCE

CVE-2025-71092Firmware, BMC & network fabriccurated

Impact

Out-of-bounds write in the Broadcom RoCE driver's error-statistics copy, introduced when three RoCE hardware counters were added past the end of the existing array. Reading RDMA counters is something monitoring agents do constantly on an AI cluster, so the vulnerable path runs on a schedule whether or not anyone attacks it.

Who can reach it

Triggered by reading RoCE hardware counters — reachable from any local process permitted to query RDMA statistics, including monitoring agents.

What to do

Kernel/driver upgrade plus host reboot. Interim: stop polling RoCE hardware counters on Broadcom adapters, which costs you fabric observability — usually a worse trade than patching.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.