Executive brief
A vulnerability was identified in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem, which manages high-speed data transfers between computers. An attacker could potentially bypass security checks by using a specially crafted block device to impersonate a legitimate character device. This could lead to unauthorized access to system capabilities or data handled by the RDMA component.
Technical details
A vulnerability in the Linux kernel RDMA subsystem exists within the ib_get_ucaps() function in drivers/infiniband/core/ucaps.c. The root cause is an insufficient validation of file descriptors; the code previously relied solely on dev_t for identification. Because character and block devices can share the same dev_t (aliasing), a local attacker could use a block device to masquerade as a UCAP character device. The fix introduces a check of the file operations (f_ops) to ensure the file descriptor belongs to an authentic ucaps_cdev. This prevents unauthorized users from gaining UCAP privileges through device impersonation.
Affected products
- Linux Linux 6.15 to 6.18.35, 7.0 to 7.0.12
Timeline
- 2026-05-26: other: Initial fix authored
- 2026-06-25: disclosed: CVE published