Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/ionic: Embed counter driver data in rdma_counter allocation

Commit 7e53b31acc7f ("RDMA/core: Create and destroy rdma_counter using
rdma_zalloc_drv_obj()") requires drivers implementing counter ops to
embed struct rdma_counter in a driver-specific struct, register its size
via INIT_RDMA_OBJ_SIZE, and provide a counter_init callback.

The ionic driver was merged without this adaptation, causing a NULL
pointer dereference in alloc_and_bind() since rdma_zalloc_drv_obj()
allocates zero bytes when size_rdma_counter is unset.

Consolidate struct ionic_counter into a new struct ionic_rdma_counter
that embeds struct rdma_counter, replace the xarray with a lightweight
ida for ID allocation, and add the required counter_init and
INIT_RDMA_OBJ_SIZE declarations.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The ionic RDMA driver fails to register the size of its embedded rdma_counter structure during initialization, causing rdma_zalloc_drv_obj to allocate zero bytes. When alloc_and_bind attempts to use the counter, it dereferences a NULL pointer and the kernel panics. The weakness is a NULL pointer dereference (CWE-476) and the ultimate effect is a system-wide crash, resulting in a denial of service.

Affected Systems

All Linux kernel releases that ship the ionic RDMA driver without the application of commit 7e53b31 (which registers INIT_RDMA_OBJ_SIZE) are affected. This includes any distribution kernel where the ionic RDMA module is loaded. If RDMA is disabled or the driver is not present the vulnerability does not manifest.

Risk and Exploitability

The CVSS score of 4.1 indicates low severity. The EPSS score of < 1% implies a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker would need the ability to load or enable the ionic RDMA driver, which typically requires root privileges or the use of signed modules. The likely attack vector is local privilege or kernel module load; upon successful exploitation, a kernel crash occurs, causing a reboot or shutdown.

Generated by OpenCVE AI on September 15, 2026 at 22:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version containing commit 7e53b31 or later so the ionic RDMA driver correctly registers the counter size and performs initialization.
  • If a kernel update cannot be applied immediately, blacklist or otherwise prevent the ionic RDMA driver from loading by adding it to a module blacklist configuration file.
  • Enforce strict module‑signing policies and limit module loading to trusted users; monitor kernel logs for RDMA or ionic driver activity to detect accidental or malicious loading attempts.

Generated by OpenCVE AI on September 15, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: Embed counter driver data in rdma_counter allocation Commit 7e53b31acc7f ("RDMA/core: Create and destroy rdma_counter using rdma_zalloc_drv_obj()") requires drivers implementing counter ops to embed struct rdma_counter in a driver-specific struct, register its size via INIT_RDMA_OBJ_SIZE, and provide a counter_init callback. The ionic driver was merged without this adaptation, causing a NULL pointer dereference in alloc_and_bind() since rdma_zalloc_drv_obj() allocates zero bytes when size_rdma_counter is unset. Consolidate struct ionic_counter into a new struct ionic_rdma_counter that embeds struct rdma_counter, replace the xarray with a lightweight ida for ID allocation, and add the required counter_init and INIT_RDMA_OBJ_SIZE declarations.
Title RDMA/ionic: Embed counter driver data in rdma_counter allocation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:55.336Z

Reserved: 2026-09-11T19:38:34.716Z

Link: CVE-2026-89509

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:33.273

Modified: 2026-09-11T20:19:33.273

Link: CVE-2026-89509

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:43:55Z

Links: CVE-2026-89509 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:30:15Z

Weaknesses