Impact
Remote Direct the function for tearing down the RDS InfiniBand transport leaves a stale pointer to the i_sends send ring in memory when a setup failure occurs. Subsequent pointer as a valid that can corrupt memory. This flaw is identified as CWE-825.
Affected Systems
Linux kernels that contain prior to the commit that clears i_sends during the error unwind path are affected. The vulnerability is present in any distribution kernel that exposes the RDS/IB transport layer without the fix, regardless of kernel version, because no specific version is listed.
Risk and Exploitability
The CVSS score of 9.8 signifies a critical severity. The EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. As the vulnerability is not listed in the CISA KEV catalog, there is no known public exploitation at the time of analysis. Exploitation requires triggering a failed RDS InfiniBand connection setup followed by a teardown; the description does not specify whether remote or local access or privilege escalation is required, so the attack surface remains uncertain. Consequently, the risk rating is high but the actual exploitation likelihood is low based on available metrics.
OpenCVE Enrichment
Debian DLA