Impact
In the Linux kernel’s RDMA/cxgb4 driver, a registration work queue (reg_work) can be scheduled while an RDMA device is simultaneously being removed. If the device context (ctx->dev) is freed while this work is pending or running, the registration routine may access the already‑deallocated memory, resulting in a use‑after‑ crash, potentially disrupting system availability. The bug was identified by static analysis and is fixed by cancelling the registration work before the device is freed. The weakness corresponds to CWE-825.
Affected Systems
The vulnerability applies to any Linux system that includes the cxgb4 RDMA driver within the kernel. The vendor list indicates Linux kernels themselves; specific kernel versions are not enumerated in the CVE data, so all builds that contain this driver are potentially exposed until a patch is applied.
Risk and Exploitability
CVSS score is 7.8, and the EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. The likely attack vector is local kernel access; it is inferred that an attacker must trigger a device removal while registration work is queued to exploit the weakness. The effect is expected to be a kernel crash or process termination rather than arbitrary code execution, as the description does not state such outcomes.
OpenCVE Enrichment
Debian DSA