Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46127

Опубликовано: 28 мая 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() Sashiko points out that pd->uctx isn't initialized until late in the function so all these error flow references are NULL and will crash. Use the uctx that isn't NULL.

A flaw was found in the Linux kernel, specifically within the RDMA (Remote Direct Memory Access) ocrdma driver. This vulnerability arises from an uninitialized pointer in the ocrdma_copy_pd_uresp() function's error handling, which can lead to a NULL dereference. An attacker could exploit this to cause a system crash, resulting in a Denial of Service (DoS).

Отчет

This Moderate-severity flaw in the Linux kernel's RDMA ocrdma driver can lead to a system crash and denial of service. The vulnerability, caused by an uninitialized pointer in error handling, requires local access to a system with the ocrdma driver loaded for exploitation. Red Hat Enterprise Linux 6 and 7 are affected.

Меры по смягчению последствий

To prevent the ocrdma kernel module from loading, blacklist it by creating a file /etc/modprobe.d/blacklist-ocrdma.conf with the content blacklist ocrdma. After saving the file, regenerate the initramfs using dracut -f -v and reboot the system for the changes to take effect. This action may affect functionality dependent on the ocrdma driver and RDMA hardware.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelFix deferred
Red Hat Enterprise Linux 7kernel-rtFix deferred
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2482582kernel: RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp()

EPSS

Процентиль: 3%
0.00128
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() Sashiko points out that pd->uctx isn't initialized until late in the function so all these error flow references are NULL and will crash. Use the uctx that isn't NULL.

CVSS3: 5.5
nvd
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() Sashiko points out that pd->uctx isn't initialized until late in the function so all these error flow references are NULL and will crash. Use the uctx that isn't NULL.

msrc
2 месяца назад

RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp()

CVSS3: 5.5
debian
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: R ...

CVSS3: 5.5
github
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() Sashiko points out that pd->uctx isn't initialized until late in the function so all these error flow references are NULL and will crash. Use the uctx that isn't NULL.

EPSS

Процентиль: 3%
0.00128
Низкий

5.5 Medium

CVSS3