SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-89509

UNKNOWN · CVSS N/A EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the ionic driver in the Linux kernel, where a NULL pointer dereference occurs in the alloc_and_bind() function due to improper handling of the rdma_counter structure. This flaw can lead to system crashes or instability when the driver attempts to allocate resources without the necessary size configuration. Organizations using Linux systems with RDMA capabilities, particularly those relying on the ionic driver, should prioritize addressing this issue to maintain system reliability and performance.

CVE
CVE-2026-89509
Severity
UNKNOWN
CVSS
N/A
EPSS
0.20%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: Embed counter driver data in rdma_counter allocation Commit 7e53b31acc7f ("RDMA/core: Create and destroy rdma_counter using rdma_zalloc_drv_obj()") requires drivers implementing counter ops to embed struct rdma_counter in a driver-specific struct, register its size via INIT_RDMA_OBJ_SIZE, and provide a counter_init callback. The ionic driver was merged without this adaptation, causing a NULL pointer dereference in alloc_and_bind() since rdma_zalloc_drv_obj() allocates zero bytes when size_rdma_counter is unset. Consolidate struct ionic_counter into a new struct ionic_rdma_counter that embeds struct rdma_counter, replace the xarray with a lightweight ida for ID allocation, and add the required counter_init and INIT_RDMA_OBJ_SIZE declarations.