Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR

The original commit missed that three drivers (mthca, irdma, siw) have UHW
data associated with reg_mr that cannot be passed through the ioctl. They
also assume that the udata cannot be NULL, so failing to pass a valid
udata can trigger a NULL udata crash in those drivers.

This never happens in real systems since in rdma-core ibv_cmd_reg_mr_ex()
does not accept a udata and those three drivers don't use it, however a
malicious userspace could trigger it.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A null pointer dereference occurs in the RDMA uverbs subsystem when a REG_MR ioctl is processed with a NULL udata field. The drivers mthca, irdma, and siw expect a non‑null udata pointer and crash when one is not provided, triggering a kernel bug mapped to CWE‑476.

Affected Systems

The Linux kernel RDMA drivers mthca, irdma, and siw are affected. Any kernel build that includes these drivers without applying the patch that adds support for UVERBS_ATTR_UHW to the REG_MR operation is vulnerable; the patch is introduced in commit 011199f46f44a9f. Distribution kernel versions still using the older code path are impacted.

Risk and Exploitability

The CVSS score of 4.7 indicates low‑to‑moderate severity, and the EPSS score is below 1 %. The vulnerability is not listed in CISA KEV. Exploitation requires a local user with permission to issue RDMA ioctls; remote exploitation without RDMA device access is not feasible. A local attacker can trigger a kernel crash and thereby cause a denial of service.

Generated by OpenCVE AI on September 15, 2026 at 22:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the patch adding UVERBS_ATTR_UHW handling (e.g., after commit 011199f46f44a9f).
  • Unload or disable the mthca, irdma, and siw modules if the system does not require RDMA functionality.
  • Restrict write or ioctl access to the RDMA device nodes (e.g., /dev/infiniband/*) so only trusted users or system processes can issue commands.

Generated by OpenCVE AI on September 15, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR The original commit missed that three drivers (mthca, irdma, siw) have UHW data associated with reg_mr that cannot be passed through the ioctl. They also assume that the udata cannot be NULL, so failing to pass a valid udata can trigger a NULL udata crash in those drivers. This never happens in real systems since in rdma-core ibv_cmd_reg_mr_ex() does not accept a udata and those three drivers don't use it, however a malicious userspace could trigger it.
Title RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:53.350Z

Reserved: 2026-09-11T19:38:34.716Z

Link: CVE-2026-89506

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:32.917

Modified: 2026-09-11T20:19:32.917

Link: CVE-2026-89506

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:43:53Z

Links: CVE-2026-89506 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:30:15Z

Weaknesses