Impact
A kernel bug in the RDMA uverbs subsystem can cause the kernel to dereference an uninitialized method_elm pointer when a legacy bundle that lacks an ioctl method element is processed. If a malformed provider input triggers the common uverbs validation to emit an error message, uverbs_get_handler_fn() will attempt to access this dangling pointer, resulting in a kernel crash. The crash manifests as a kernel panic, which denies service to all users on the affected machine.
Affected Systems
Any Linux kernel build that exposes RDMA uverbs interfaces without the patch is potentially impacted. Because no vendor‑specific version list is that allows interaction with RDMA device nodes may be affected. The flaw resides in the core uverbs implementation used by RDMA drivers and does not depend on a particular distro's kernel configuration.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires local or privileged access to RDMA devices, as an attacker must supply malformed RDMA bundles to the uverbs subsystem. The effect is a kernel crash that leads to denial of service, with no evidence of remote code execution or confidentiality compromise.
OpenCVE Enrichment