Impact
The vulnerability resides in the RDMA/hfi1 driver of the Linux kernel. The function sdma_txinit_ahg() may return an error during the initialization of a transaction request, but the caller set_txreq_header_ahg() ignores this failure and proceeds as if the initialization succeeded. The result is that the kernel uses an uninitialized tx->txreq field, which can lead to processing of malformed RDMA traffic. This invalid kernel state can trigger a panic or other forms of instability, effectively denying service to the host OS and any RDMA clients it serves.
Affected Systems
All Linux kernel implementations that incorporate the unpatched RDMA/hfi1 driver are affected. The flaw applies to any distribution shipping a generic Linux kernel that has not yet integrated the kernel commits referenced in the provided Git links. No specific version range is supplied, so any kernel revision lacking the cited fix should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity flaw. The EPSS score is reported as < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers would most likely need local or privileged access to the RDMA device or ability to inject crafted RDMA traffic that triggers the error path in sdma_txinit_ahg(). This inference comes from the description that the failure originates in kernel‑space RDMA handling, implying a local execution or privileged RDMA usage scenario. No public exploit is known, but the low exploitation probability does not diminish the potential impact of a kernel panic, necessitating prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA