Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/hfi1: Propagate sdma_txinit_ahg() errors

set_txreq_header_ahg() ignores the return value of sdma_txinit_ahg().

If sdma_txinit_ahg() fails, it returns before initializing tx->txreq.
However, set_txreq_header_ahg() ignores the error and returns the AHG
change count, causing the caller to continue processing the request as
though initialization had succeeded.

Propagate sdma_txinit_ahg() failures to the caller and abort request
processing when initialization fails.

Found by Linux Verification Center (linuxtesting.org) with SVACE.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the RDMA/hfi1 driver of the Linux kernel. The function sdma_txinit_ahg() may return an error during the initialization of a transaction request, but the caller set_txreq_header_ahg() ignores this failure and proceeds as if the initialization succeeded. The result is that the kernel uses an uninitialized tx->txreq field, which can lead to processing of malformed RDMA traffic. This invalid kernel state can trigger a panic or other forms of instability, effectively denying service to the host OS and any RDMA clients it serves.

Affected Systems

All Linux kernel implementations that incorporate the unpatched RDMA/hfi1 driver are affected. The flaw applies to any distribution shipping a generic Linux kernel that has not yet integrated the kernel commits referenced in the provided Git links. No specific version range is supplied, so any kernel revision lacking the cited fix should be considered vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity flaw. The EPSS score is reported as < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers would most likely need local or privileged access to the RDMA device or ability to inject crafted RDMA traffic that triggers the error path in sdma_txinit_ahg(). This inference comes from the description that the failure originates in kernel‑space RDMA handling, implying a local execution or privileged RDMA usage scenario. No public exploit is known, but the low exploitation probability does not diminish the potential impact of a kernel panic, necessitating prompt remediation.

Generated by OpenCVE AI on September 20, 2026 at 00:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that propagates sdma_txinit_ahg() errors by upgrading to a kernel release containing the fix or by applying the specific commit(s) from the Git repository links. Rebuild the RDMA/hfi1 module against the current kernel headers to ensure compatibility.
  • After applying the patch or upgrading the kernel, reboot the system or reload the RDMA/hfi1 module so that the updated driver is active in the kernel.
  • If an immediate patch or upgrade is not possible, disable the RDMA/hfi1 driver or block RDMA traffic at the network layer to prevent use of the vulnerable code. Alternatively, restrict RDMA device access to trusted users only.

Generated by OpenCVE AI on September 20, 2026 at 00:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457

Sat, 19 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-390

Sat, 19 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-390

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Propagate sdma_txinit_ahg() errors set_txreq_header_ahg() ignores the return value of sdma_txinit_ahg(). If sdma_txinit_ahg() fails, it returns before initializing tx->txreq. However, set_txreq_header_ahg() ignores the error and returns the AHG change count, causing the caller to continue processing the request as though initialization had succeeded. Propagate sdma_txinit_ahg() failures to the caller and abort request processing when initialization fails. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Title RDMA/hfi1: Propagate sdma_txinit_ahg() errors
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:40.342Z

Reserved: 2026-09-17T15:57:05.656Z

Link: CVE-2026-93037

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:56.750

Modified: 2026-09-18T18:18:18.580

Link: CVE-2026-93037

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:45:16Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable