Impact
A flaw in the Linux kernel’s remote‑direct memory access (rdma) listener creation path causes a reference counter imbalance; the code path bypasses the normal cleanup routine and frees memory directly. This can leave the network namespace and module reference counts unbalanced, leading to a memory leak and, if the imbalance occurs frequently, to a kernel crash or other instability. The weakness is classified as CWE‑772, a reference count error. The vulnerability itself does not disclose data or allow code execution, but it jeopardizes the reliability of the kernel.
Affected Systems
All Linux kernel distributions that include the svcrdma module before the vendor’s patch are affected. The vulnerability is present in any kernel that ships with the unpatched svcrdma code, regardless of specific release version, as the affected code exists before the recent commit that applies the fix.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate risk level. Because the EPSS score is less than 1 % the probability of exploitation is inferred to be low, but the vulnerability is not cataloged in CISA’s known exploited vulnerabilities list. Exploitation would require a local attacker with kernel/module load privileges to force the listener‑creation failure path, typically by providing malformed input or triggering module load errors. The consequence is resource exhaustion or a potential kernel panic, impacting availability but not confidentiality or integrity.
OpenCVE Enrichment