Impact
In the Linux kernel’s svcrdma module, a failure to allocate a new transport for an RDMA connection causes the connection request handler to return without releasing the allocated rdma_cm_id. Each failed allocation leaks one rdma_cm_id, which can accumulate under memory pressure of service. The weakness is an improper cleanup that results in a resource leak and is categorized as CWE-772. The CVSS score of 5.9 reflects moderate severity.
Affected Systems
The flaw is present in the Linux kernel’s svcrdma module, affecting any kernel release that includes this module and has RDMA enabled. The affected product is the Linux kernel; no specific version ranges are supplied in the current data, so all kernel versions prior to the patch are potentially vulnerable.
Risk and Exploitability
Based on the description, it is inferred that a remote RDMA client can repeatedly issue CONNECT_REQUEST events, gradually leaking rdma_cm_id objects. The flaw does not require elevated privileges; a remote RDMA client can trigger it by repeatedly initiating connection attempts. The CVSS score of 5.9 reflects moderate severity. The EPSS score of < 1% indicates a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The moderate CVSS score and low exploitation probability combine to make this a low‑to moderate‑risk vulnerability that could, however, degrade availability in sustained attack scenarios.
OpenCVE Enrichment
Debian DSA