Executive brief
A vulnerability was identified in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem that could allow a local user to cause a system crash. The issue occurs during specific processor affinity calculations, where a mathematical error (division by zero) can trigger a kernel panic. This primarily impacts system availability, potentially leading to a denial-of-service condition on affected servers.
Technical details
A divide-by-zero vulnerability exists in the find_hw_thread_mask() function within the drivers/infiniband/hw/hfi1/affinity.c component of the Linux kernel. The root cause is a logic error where the code performs a division using 'affinity->num_core_siblings' as a divisor before verifying that the value is non-zero. A local attacker with sufficient privileges to interact with RDMA interfaces could potentially trigger this condition, resulting in a kernel oops or panic (Denial of Service). The fix involves reordering the validation check to ensure the divisor is non-zero before the arithmetic operation is performed. Patches have been backported to multiple stable kernel branches including 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.12.y, 6.15.y, and 6.16.y.
Affected products
- Linux Linux Kernel 4.8 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-09-11: disclosed: Initial disclosure of the vulnerability and CVE assignment.
- 2025-08-28: patched: Fix committed to the Linux stable tree.
References
- https://git.kernel.org/stable/c/1a7cf828ed861de5be1aff99e10f114b363c19d3
- https://git.kernel.org/stable/c/31d0599a23efdbfe579bfbd1eb8f8c942f13744d
- https://git.kernel.org/stable/c/4b4317b0d758ff92ba96f4e448a8992a6fe607bf
- https://git.kernel.org/stable/c/59f7d2138591ef8f0e4e4ab5f1ab674e8181ad3a
- https://git.kernel.org/stable/c/89fdac333a17ed990b41565630ef4791782e02f5
- https://git.kernel.org/stable/c/9b05e91afe948ed819bf87d7ba0fccf451ed79a6
- https://git.kernel.org/stable/c/9bba1a9994c523b44db64f63b564b4719ea2b7ef