CVE-2026-89509
Received Received - Intake

RDMA Counter NULL Pointer Dereference in Linux Kernel

Vulnerability report for CVE-2026-89509, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: Embed counter driver data in rdma_counter allocation Commit 7e53b31acc7f ("RDMA/core: Create and destroy rdma_counter using rdma_zalloc_drv_obj()") requires drivers implementing counter ops to embed struct rdma_counter in a driver-specific struct, register its size via INIT_RDMA_OBJ_SIZE, and provide a counter_init callback. The ionic driver was merged without this adaptation, causing a NULL pointer dereference in alloc_and_bind() since rdma_zalloc_drv_obj() allocates zero bytes when size_rdma_counter is unset. Consolidate struct ionic_counter into a new struct ionic_rdma_counter that embeds struct rdma_counter, replace the xarray with a lightweight ida for ID allocation, and add the required counter_init and INIT_RDMA_OBJ_SIZE declarations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a NULL pointer dereference in the ionic RDMA driver. It occurs because the driver did not adapt to a new requirement where drivers must embed a specific struct and register its size. This caused alloc_and_bind() to fail when rdma_zalloc_drv_obj() allocated zero bytes due to missing size registration.

Detection Guidance

This vulnerability is specific to the Linux kernel's RDMA/ionic driver and may not have direct detection commands. Check if your system uses the ionic driver with RDMA functionality by running lsmod | grep ionic. If loaded, monitor kernel logs for NULL pointer dereference errors using dmesg | grep -i "ionic" or journalctl -k | grep -i "NULL pointer"

Impact Analysis

This vulnerability could lead to system crashes or instability if exploited, as it causes a NULL pointer dereference in the kernel. Users running affected Linux kernel versions with the ionic RDMA driver may experience kernel panics or denial-of-service conditions.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a Linux kernel driver issue causing a NULL pointer dereference due to improper counter object initialization in the RDMA/ionic driver. Compliance impacts would only occur if this vulnerability were exploited to compromise system integrity or data confidentiality, which is not described in the provided context.

Mitigation Strategies

Update your Linux kernel to a version that includes the fix for CVE-2026-89509. If using a distribution kernel, apply available security patches. If you are using the ionic driver, ensure it is updated to a version that embeds struct rdma_counter correctly and registers its size via INIT_RDMA_OBJ_SIZE.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89509. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart