GPU VulnDB

Database/Firmware, BMC & network fabric

RDMA / RoCE: RoCE and IB RDMA have no cryptographic authentication of the QP connection setup or of subsequent

NCVD-0000-005-rdma-roceFirmware, BMC & network fabricReDMArkcurated

Impact

RoCE and IB RDMA have no cryptographic authentication of the QP connection setup or of subsequent RDMA reads/writes; an on-fabric attacker can inject and impersonate, and remote memory reads bypass the target CPU entirely. No CVE — it is the RDMA specification

Who can reach it

Fabric-local, tenant-to-tenant

What to do

Requires fabric-level isolation (per-tenant pkeys / VXLAN-isolated RoCE domains) or PSP/IPsec offload on the NIC. Shared-fabric multi-tenancy without this is an unmitigated tenant-to-tenant read primitive

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.