Impact
A defect in the Linux kernel’s vDPA/mlx5 driver causes the error path cleanup to iterate over the wrong list, leaving newly allocated direct memory registration entries untouched. This results in a kernel‑level resource leak, which could increase kernel memory usage.
Affected Systems
All Linux kernel versions that include the vDPA/mlx5 driver before the integration of commit 6ca752850 are affected. This includes mainstream distributions that ship the upstream kernel from any release series that contains the kernel prior to the fix. Exact version ranges depend on each distribution’s kernel packaging but can be identified by examining the patch level.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability. Based on the description, it is inferred that the attack vector is local or remote only if the attacker can gain privileged kernel code execution, because the flaw requires kernel‑level privileges or the ability to execute code in kernel context to cause the memory leak. Given the low likelihood and the nature of the defect, overall risk remains low.
OpenCVE Enrichment
Debian DLA
Debian DSA