Impact
A null pointer dereference occurs in the RDMA uverbs subsystem when a REG_MR ioctl is processed with a NULL udata field. The drivers mthca, irdma, and siw expect a non‑null udata pointer and crash when one is not provided, triggering a kernel bug mapped to CWE‑476.
Affected Systems
The Linux kernel RDMA drivers mthca, irdma, and siw are affected. Any kernel build that includes these drivers without applying the patch that adds support for UVERBS_ATTR_UHW to the REG_MR operation is vulnerable; the patch is introduced in commit 011199f46f44a9f. Distribution kernel versions still using the older code path are impacted.
Risk and Exploitability
The CVSS score of 4.7 indicates low‑to‑moderate severity, and the EPSS score is below 1 %. The vulnerability is not listed in CISA KEV. Exploitation requires a local user with permission to issue RDMA ioctls; remote exploitation without RDMA device access is not feasible. A local attacker can trigger a kernel crash and thereby cause a denial of service.
OpenCVE Enrichment