Impact
The ionic RDMA driver fails to register the size of its embedded rdma_counter structure during initialization, causing rdma_zalloc_drv_obj to allocate zero bytes. When alloc_and_bind attempts to use the counter, it dereferences a NULL pointer and the kernel panics. The weakness is a NULL pointer dereference (CWE-476) and the ultimate effect is a system-wide crash, resulting in a denial of service.
Affected Systems
All Linux kernel releases that ship the ionic RDMA driver without the application of commit 7e53b31 (which registers INIT_RDMA_OBJ_SIZE) are affected. This includes any distribution kernel where the ionic RDMA module is loaded. If RDMA is disabled or the driver is not present the vulnerability does not manifest.
Risk and Exploitability
The CVSS score of 4.1 indicates low severity. The EPSS score of < 1% implies a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker would need the ability to load or enable the ionic RDMA driver, which typically requires root privileges or the use of signed modules. The likely attack vector is local privilege or kernel module load; upon successful exploitation, a kernel crash occurs, causing a reboot or shutdown.
OpenCVE Enrichment