Executive brief
The Linux kernel's RDMA/ionic driver contains a NULL pointer dereference vulnerability in its counter allocation routine. When a system attempts to allocate and bind RDMA counters, the driver fails to properly initialize required data structures, causing the kernel to crash. This can lead to denial of service on systems using InfiniBand/RDMA networking with Pensando Ionic adapters.
Technical details
The vulnerability is a NULL pointer dereference in the ionic RDMA driver's counter allocation path. The root cause is that the ionic driver was merged without adapting to a refactored RDMA core API (commit 7e53b31acc7f) that requires drivers to embed struct rdma_counter in a driver-specific struct and register its size via INIT_RDMA_OBJ_SIZE. Without this, rdma_zalloc_drv_obj() allocates zero bytes, leading to NULL pointer dereference in alloc_and_bind(). The fix consolidates ionic_counter into ionic_rdma_counter (embedding rdma_counter), replaces xarray with ida for ID allocation, and adds required counter_init and INIT_RDMA_OBJ_SIZE declarations. Attack vector is local only—exploitation requires the ability to issue RDMA counter operations, typically from userspace with appropriate permissions.
Affected products
- Linux Linux kernel 6.18 and later (affected by commit ea4c399642b8)
Timeline
- 2026-09-11: disclosed
- 2026-09-07: patched: Fix committed upstream; backported to stable branches