Impact
In the Linux kernel, a flaw in the SMBdirect RDMA accept‑failure path causes memory pools to be destroyed before the associated queue pair (QP) is drained. Because an outstanding receive I/O object is still referenced by the QP, it is freed while in use, triggering a kernel BUG that results in a crash. This classic use‑after‑free or improper resource recovery error can bring the entire system down, forcing a reboot to restore availability.
Affected Systems
The issue affects any Linux kernel that includes the SMBdirect RDMA code. No specific versions are listed, so all released kernels containing this code are potentially impacted.
Risk and Exploitability
The CVSS score is 7.5, indicating high severity. The EPSS score is below 1%, suggesting low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector, although not explicitly detailed, is remote: an attacker capable of initiating an RDMA connection to a vulnerable SMBdirect implementation could trigger the flawed cleanup path and cause a kernel crash.
OpenCVE Enrichment