CVE-2026-31425 Details
Description
In the Linux kernel, the following vulnerability has been resolved: rds: ib: reject FRMR registration before IB connection is established rds_ib_get_mr() extracts the rds_ib_connection from conn->c_transport_data and passes it to rds_ib_reg_frmr() for FRWR memory registration. On a fresh outgoing connection, ic is allocated in rds_ib_conn_alloc() with i_cm_id = NULL because the connection worker has not yet called rds_ib_conn_path_connect() to create the rdma_cm_id. When sendmsg() with RDS_CMSG_RDMA_MAP is called on such a connection, the sendmsg path parses the control message before any connection establishment, allowing rds_ib_post_reg_frmr() to dereference ic->i_cm_id->qp and crash the kernel. The existing guard in rds_ib_reg_frmr() only checks for !ic (added in commit 9e630bcb7701), which does not catch this case since ic is allocated early and is always non-NULL once the connection object exists. KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:rds_ib_post_reg_frmr+0x50e/0x920 Call Trace: rds_ib_post_reg_frmr (net/rds/ib_frmr.c:167) rds_ib_map_frmr (net/rds/ib_frmr.c:252) rds_ib_reg_frmr (net/rds/ib_frmr.c:430) rds_ib_get_mr (net/rds/ib_rdma.c:615) __rds_rdma_map (net/rds/rdma.c:295) rds_cmsg_rdma_map (net/rds/rdma.c:860) rds_sendmsg (net/rds/send.c:1363) ____sys_sendmsg do_syscall_64 Add a check in rds_ib_get_mr() that verifies ic, i_cm_id, and qp are all non-NULL before proceeding with FRMR registration, mirroring the guard already present in rds_ib_post_inv(). Return -ENODEV when the connection is not ready, which the existing error handling in rds_cmsg_send() converts to -EAGAIN for userspace retry and triggers rds_conn_connect_if_down() to start the connection worker.
A vulnerability in the Linux kernel's RDS (Reliable Datagram Sockets) implementation over InfiniBand (IB) has been identified. The issue arises in the memory registration process for a fresh outgoing connection, where the connection object is not fully established. Specifically, the connection worker has not yet created the necessary RDMA connection identifier. When the 'sendmsg' function is called with the RDS control message for RDMA mapping, the system attempts to access a part of the connection that is not yet ready, leading to a null pointer dereference and a kernel crash. This vulnerability affects several versions of the Linux kernel.
The vulnerability has been addressed in the Linux kernel. Users should upgrade to the latest version where this issue has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/23e07c340c445f0ebff7757ba15434cb447eb662 | kernel.org | Patch |
| https://git.kernel.org/stable/c/450ec93c0f172374acbf236f1f5f02d53650aa2d | kernel.org | Patch |
| https://git.kernel.org/stable/c/47de5b73db3b88f45c107393f26aeba26e9e8fae | kernel.org | Patch |
| https://git.kernel.org/stable/c/6b0a8de67ac0c74e1a7df92b73c862cb36780dfc | kernel.org | Patch |
| https://git.kernel.org/stable/c/82e4a3b56b23b844802056c9e75a39d24169b0a4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a54ecccfae62c5c85259ae5ea5d9c20009519049 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a5bfd14c9a299e6db4add4440430ee5e010b03ad | kernel.org | Patch |
| https://git.kernel.org/stable/c/c506456ebf84c50ed9327473d4e9bd905def212b | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.6, < 5.10.253 >= 5.11, < 5.15.203 >= 5.16, < 6.1.168 >= 6.2, < 6.6.134 >= 6.7, < 6.12.81 >= 6.13, < 6.18.22 >= 6.19, < 6.19.12 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 20, 2026 | Initial Analysis | [email protected] |
| Apr 18, 2026 | CVE Modified | kernel.org |
| Apr 13, 2026 | New CVE Received | kernel.org |