Impact
The Linux kernel’s RDMA transport contains a use‑after‑free flaw that arises when rpcrdma_rn_unregister is invoked after rdma_destroy_id, leaving a dangling reference in the device’s xarray. A concurrent ib_unregister_device walk can trigger svc_rdma_xprt_done against that freed structure, corrupting kernel memory. This vulnerability is classified as CWE‑825 and can be leveraged by a local attacker with control over RDMA services to gain privilege escalation.
Affected Systems
All installations of the Linux kernel that have not yet applied the commit ordering the rpcrdma_rn_unregister before rdma_destroy_id and the added NULL check are affected. The commit hash references indicate the fix was made in the stable tree; therefore systems running kernel releases prior to that commit are at risk.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score of <1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access and the presence of a race condition between rdma_destroy_id and rpcrdma_rn_unregister, making it difficult to achieve in practice. Nonetheless, the potential for kernel compromise warrants timely remediation.
OpenCVE Enrichment
Debian DSA