-

CVE-2026-68418

RDMA/irdma: Prevent user-triggered null deref on QP create

In the Linux kernel, the following vulnerability has been resolved:

RDMA/irdma: Prevent user-triggered null deref on QP create

Previously, the user QP creation path would only attempt to
populate iwqp->iwpbl if the user-provided req.user_wqe_bufs
field was non-zero. The problem is that iwqp->iwpbl is
unconditionally dereferenced later on in irdma_setup_virt_qp.

While there was a check for iwqp->iwpbl != NULL, this check
would only occur if req.user_wqe_bufs was non-zero. The end
result is that a user could send a zero user_wqe_bufs value
and trigger a null ptr deref.

Fix this by unconditionally calling irdma_get_pbl and bailing
if it fails, similar to the CQ and SRQ paths.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b48c24c2d710cf34810c555dcef883a3d35a9c08
Version < ec675b4cdfd378d8c9dd8c93126c024f2469bd79
Status affected
Version b48c24c2d710cf34810c555dcef883a3d35a9c08
Version < 728211c815f6eef28dd3df2a5b6297483185aa20
Status affected
Version b48c24c2d710cf34810c555dcef883a3d35a9c08
Version < b9b0889071569d43623c260074e159cd8f26adb1
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.14
Status affected
Version 0
Version < 5.14
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.051
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ec675b4cdfd378d8c9dd8c93126c024f2469bd79
https://git.kernel.org/stable/c/728211c815f6eef28dd3df2a5b6297483185aa20
https://git.kernel.org/stable/c/b9b0889071569d43623c260074e159cd8f26adb1