Impact
The flaw occurs in the RDMA/cma part of the Linux kernel where a warning is triggered when a resource with a NULL device pointer is added to the restrack. The warning originates from a WARN_ON assertion in res_to_rt(), indicating a potential null‑pointer dereference that could lead to a kernel crash and service disruption. The bug is caused by unconditional resource addition even though device acquisition may have failed. Since the code path involves asynchronous RDMA address resolution, the warning would surface during RDMA traffic handling.
Affected Systems
Linux kernel builds that include the RDMA/cma subsystem prior to the fix. Any distribution or custom kernel that compiles the ib_device stack and does not contain the patch is affected. No specific version numbers are provided, but the issue applies to all kernels shipped without the documented change.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in CISA KEV, indicating a low probability of exploitation. The warning occurs during asynchronous RDMA address resolution, which typically requires RDMA traffic to be processed by the kernel; this is inferred to be a local or state‑dependent action but is not explicitly stated in the data. No known exploits or confirmed crash reports are cited. Consequently, the risk is low, with the principal concern being potential denial‑of‑service via kernel instability if the bug is triggered repeatedly.
OpenCVE Enrichment
Debian DLA
Debian DSA