Impact
A race condition exists in the Linux kernel RDMA UCMA subsystem where ucma_write_cm_event() reads ctx->file multiple times without holding the handler lock while a concurrent ucma_migrate_id() may change it between reads. This can lead to corruption of the kernel linked‑list that queues uevents, causing a kernel BUG, leaving a mutex locked forever and hanging subsequent writers. The outcome is a local denial of service that can force the system to become unavailable or crash.
Affected Systems
All Linux kernels that include the UCMA CM code and expose the /dev/infiniband/rdma_cm character device with mode 0666 are affected until the upstream fix is applied. No specific release versions are listed, so any kernel that contains the UCMA core and the RDMA CM device is vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation is currently documented. The likely attack vector is local, requiring an unprivileged user to interact with /dev/infiniband/rdma_cm and trigger the race that leads to list corruption and a deadlock.
OpenCVE Enrichment