« Volver al listado

CVE-2026-89509

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

RDMA/ionic: Embed counter driver data in rdma_counter allocation

Commit 7e53b31acc7f ("RDMA/core: Create and destroy rdma_counter using rdma_zalloc_drv_obj()") requires drivers implementing counter ops to embed struct rdma_counter in a driver-specific struct, register its size via INIT_RDMA_OBJ_SIZE, and provide a counter_init callback.

The ionic driver was merged without this adaptation, causing a NULL pointer dereference in alloc_and_bind() since rdma_zalloc_drv_obj() allocates zero bytes when size_rdma_counter is unset.

Consolidate struct ionic_counter into a new struct ionic_rdma_counter that embeds struct rdma_counter, replace the xarray with a lightweight ida for ID allocation, and add the required counter_init and INIT_RDMA_OBJ_SIZE declarations.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89509",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ea4c399642b85dc30f44d90ee805c6a18fa03062",
              "lessThan": "c98197ee3cd28288da13dc9881bb9e74daa7cbbc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ea4c399642b85dc30f44d90ee805c6a18fa03062",
              "lessThan": "08b8630b557828aedb1d9ef0a6e2ec421f334ee2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ea4c399642b85dc30f44d90ee805c6a18fa03062",
              "lessThan": "cf3ebd89e754015625fee90aa938f6bc79a2c974",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/infiniband/hw/ionic/ionic_hw_stats.c",
            "drivers/infiniband/hw/ionic/ionic_ibdev.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/infiniband/hw/ionic/ionic_hw_stats.c",
            "drivers/infiniband/hw/ionic/ionic_ibdev.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:33.273",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/08b8630b557828aedb1d9ef0a6e2ec421f334ee2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c98197ee3cd28288da13dc9881bb9e74daa7cbbc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cf3ebd89e754015625fee90aa938f6bc79a2c974",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/ionic: Embed counter driver data in rdma_counter allocation\n\nCommit 7e53b31acc7f (\"RDMA/core: Create and destroy rdma_counter using\nrdma_zalloc_drv_obj()\") requires drivers implementing counter ops to\nembed struct rdma_counter in a driver-specific struct, register its size\nvia INIT_RDMA_OBJ_SIZE, and provide a counter_init callback.\n\nThe ionic driver was merged without this adaptation, causing a NULL\npointer dereference in alloc_and_bind() since rdma_zalloc_drv_obj()\nallocates zero bytes when size_rdma_counter is unset.\n\nConsolidate struct ionic_counter into a new struct ionic_rdma_counter\nthat embeds struct rdma_counter, replace the xarray with a lightweight\nida for ID allocation, and add the required counter_init and\nINIT_RDMA_OBJ_SIZE declarations."
    }
  ],
  "lastModified": "2026-09-11T20:19:33.273",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}