Impact
In the Linux kernel the bnxt_re RDMA driver incorrectly allows a read‑only memory mapping to be upgraded to writable through an mprotect call. The original mmap check rejects VM_WRITE for the database request buffer (DBR) and toggle page pages, yet a mapping can still retain the VM_MAYWRITE flag. If an attacker later performs an mprotect(PROT_WRITE), the kernel bypasses the write restriction that was only applied during mmap, enabling arbitrary writes to these kernel pages. The result is that an unauthorized user can modify critical kernel memory controlled by the RDMA subsystem, which could lead to privilege escalation or denial of service.
Affected Systems
This flaw affects any Linux system that uses the bnxt_re RDMA driver, typically the kernel itself across all distributions. No particular kernel versions are listed in the CNA data, so all current releases that include the driver are potentially impacted.
Risk and Exploitability
The EPSS score indicates less than one percent likelihood of exploitation at present and the issue is not present in the CISA KEV catalog, suggesting a low exploitation probability. The vulnerability is local to the RDMA device; an attacker would need write access to the device or privileged user rights adjacent to the vendor’s driver. The attack path does not require remote network access, but an untrusted user with kernel module privileges could exploit the flaw after the driver loads.
OpenCVE Enrichment
Debian DLA
Debian DSA