Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/uverbs: Guard legacy bundles without method_elm

The legacy write() path dispatches through a uverbs_api_write_method, but
the uverbs_attr_bundle passed to provider code does not have an ioctl
method element. If malformed provider input causes the common uverbs
validation code to emit an error message, uverbs_get_handler_fn()
dereferences the uninitialized method_elm pointer.

Initialize method_elm explicitly for legacy bundles and make
uverbs_get_handler_fn() return NULL when no ioctl method is present. The
legacy dispatcher continues to use its local write method, while the ioctl
path continues to use the registered ioctl handler.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A kernel bug in the RDMA uverbs subsystem can cause the kernel to dereference an uninitialized method_elm pointer when a legacy bundle that lacks an ioctl method element is processed. If a malformed provider input triggers the common uverbs validation to emit an error message, uverbs_get_handler_fn() will attempt to access this dangling pointer, resulting in a kernel crash. The crash manifests as a kernel panic, which denies service to all users on the affected machine.

Affected Systems

Any Linux kernel build that exposes RDMA uverbs interfaces without the patch is potentially impacted. Because no vendor‑specific version list is that allows interaction with RDMA device nodes may be affected. The flaw resides in the core uverbs implementation used by RDMA drivers and does not depend on a particular distro's kernel configuration.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires local or privileged access to RDMA devices, as an attacker must supply malformed RDMA bundles to the uverbs subsystem. The effect is a kernel crash that leads to denial of service, with no evidence of remote code execution or confidentiality compromise.

Generated by OpenCVE AI on September 15, 2026 at 22:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel version that includes the fix which initializes the method_elm pointer in the RDMA uverbs code.
  • If the patch cannot be applied immediately, unload or disable RDMA drivers and restrict access to RDMA device nodes so that only privileged users can interact with them.
  • As an interim mitigation, block or limit RDMA traffic from untrusted users by configuring firewall rules or disabling RDMA support in the kernel configuration if RDMA services are not required.

Generated by OpenCVE AI on September 15, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-824
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Guard legacy bundles without method_elm The legacy write() path dispatches through a uverbs_api_write_method, but the uverbs_attr_bundle passed to provider code does not have an ioctl method element. If malformed provider input causes the common uverbs validation code to emit an error message, uverbs_get_handler_fn() dereferences the uninitialized method_elm pointer. Initialize method_elm explicitly for legacy bundles and make uverbs_get_handler_fn() return NULL when no ioctl method is present. The legacy dispatcher continues to use its local write method, while the ioctl path continues to use the registered ioctl handler.
Title RDMA/uverbs: Guard legacy bundles without method_elm
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:52.690Z

Reserved: 2026-09-11T19:38:34.716Z

Link: CVE-2026-89505

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:32.807

Modified: 2026-09-11T20:19:32.807

Link: CVE-2026-89505

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:43:52Z

Links: CVE-2026-89505 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:30:15Z

Weaknesses
  • CWE-824

    Access of Uninitialized Pointer