PT-2026-32351 · Linux · Linux Kernel

Published

2026-04-13

·

Updated

2026-04-20

·

CVE-2026-31425

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Reliable Delivery Service (RDS) implementation for InfiniBand (IB). The function rds ib get mr() allows FRMR memory registration to proceed before an IB connection is fully established. Specifically, when sendmsg() is called with RDS CMSG RDMA MAP on a new outgoing connection, the system may attempt to dereference ic->i cm id->qp before the rdma cm id is created, leading to a kernel crash via a null pointer dereference. This occurs because the existing check in rds ib reg frmr() only verifies if the connection object ic is non-NULL, but does not verify if the underlying connection identifiers are initialized.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-31425
ECHO-856B-9356-26F1

Affected Products

Linux Kernel