Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/hfi1: Preserve unit 0 on allocation failure

hfi1_free_devdata() assumes that the device was inserted into the unit
table and unconditionally erases dd->unit. If xa_alloc_irq() fails, the
zero-initialized unit remains zero, so full cleanup can remove an
unrelated device from index 0.

Release only the rdmavt allocation and return immediately while the unit
table has not acquired the device.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via unintended RDMA device removal
Action: Apply Patch
AI Analysis

Impact

The Linux kernel's RDMA/hfi1 driver contains a logic flaw in the hfi1_free_devdata function. It assumes the device has already been inserted into the unit table and unconditionally clears dd->unit. When xa_alloc_irq() fails, the zero‑initialized unit remains at index 0, so the subsequent cleanup step can inadvertently delete an unrelated device from that slot. This unintended device removal disables RDMA functionality for the affected system and can disrupt services that rely on remote direct memory access.

Affected Systems

The vulnerability touches the Linux kernel’s RDMA/hfi1 subsystem. No version range is specified in the data, so any kernel build that includes the existing handling logic and has not been updated with the described fix is potentially affected. Administrators should treat all unpatched Linux kernel installations as susceptible until a release that incorporates the commit restoring proper unit handling is applied.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not currently listed in CISA’s KEV catalogue. The flaw is limited to kernel-space execution and requires conditions that cause an allocation failure during device initialization, which is unlikely to be triggered without local or physical access. Nevertheless, the impact—removal of an RDMA device—can lead to service interruption on affected hosts. Given the low likelihood but definitive potential for denial of service, operators should be aware of the issue even if the exploit risk remains modest.

Generated by OpenCVE AI on September 19, 2026 at 07:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix for hfi1_free_devdata, ensuring proper unit handling during allocation failures.
  • If an immediate kernel upgrade is not feasible, disable RDMA/hfi1 services on critical nodes or isolate affected devices to prevent unintended removal.
  • Monitor kernel logs for mentions of “hfi1_free_devdata” or unexpected RDMA device detachment to detect potential exploitation attempts.

Generated by OpenCVE AI on September 19, 2026 at 07:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Preserve unit 0 on allocation failure hfi1_free_devdata() assumes that the device was inserted into the unit table and unconditionally erases dd->unit. If xa_alloc_irq() fails, the zero-initialized unit remains zero, so full cleanup can remove an unrelated device from index 0. Release only the rdmavt allocation and return immediately while the unit table has not acquired the device.
Title RDMA/hfi1: Preserve unit 0 on allocation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:15.105Z

Reserved: 2026-09-17T16:02:15.085Z

Link: CVE-2026-93103

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:04.607

Modified: 2026-09-17T17:18:04.607

Link: CVE-2026-93103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:00:11Z

Weaknesses