Impact
In the Linux kernel’s RDMA/nldev netlink interface the nested attribute RDMA_NLDEV_ATTR_STAT_HWCOUNTERS is erroneously allowed to have children of arbitrary length because the top‑level policy only checks the container size. The code proceeds to call nla_get_u32 on each child without validating that the payload is exactly one 32‑bit integer. Based on the description, it is inferred that this can trigger an out‑of‑bounds read and may cause a kernel fault, which in turn could be escalated to arbitrary code execution. The underlying weakness is improper bounds checking.
Affected Systems
The flaw resides in the Linux kernel itself and therefore applies to all distributions that ship an unmodified kernel containing the buggy RDMA/nldev code. No specific product version list is provided, so any kernel build without the patch is affected. The issue affects every architecture supported by the kernel because it lies in generic netlink parsing code used by RDMA interfaces.
Risk and Exploitability
The EPSS score for this vulnerability is less than 1%, indicating very low exploitation probability in the wild. It is not listed in the CISA KEV catalog. Although the CVSS severity is not given explicitly, the potential for kernel crash or privilege escalation classifies the risk as high. Based on the description, it is inferred that the likely attack vector involves an attacker who can send crafted netlink messages to the kernel, such as a local privileged user or an application that interfaces with RDMA. If the attacker can target the RDMA netlink socket, they can exploit the out‑of‑bounds read to destabilize the system or potentially execute code with kernel privileges. Therefore, applying the proper kernel patch is required to mitigate the risk.
OpenCVE Enrichment
Debian DLA
Debian DSA