Impact
This vulnerability in the Linux kernel’s svcrdma module is a use‑after‑free flaw identified as CWE‑825. When an RDMA address‑change event triggers the listener replacement handler, a new communication identifier (cm_id) is allocated. If that allocation fails, the existing pointer sc_cm_id is not cleared, leaving a dangling reference. A later detachment call dereferences this stale pointer, which can cause the kernel to crash and provide an attacker with a denial‑of‑service condition.
Affected Systems
This vulnerability affects Linux kernel svcrdma code before the change that cleared sc_cm_id on allocation failure. The issue remains in any kernel that has not yet incorporated the upstream commit providing the fix.
Risk and Exploitability
The CVSS score of 8.8 classifies this issue as high severity. The EPSS score of less than 1 % indicates a very low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Exposing a system to RDMA address‑change events is required for exploitation; this typically implies local or elevated privileges to trigger the event, but the description does not specify the exact prerequisites. The likely attack vector involves triggering an RDMA address‑change event that causes the listener replacement logic to run. Based on the description, it is inferred that the attacker would need to influence or observe RDMA events, which suggests a local or elevated‑privilege scenario.
OpenCVE Enrichment