Impact
In the Linux kernel, SMB Direct connection setup creates RDMA completion queues but destroys them with ib_destroy_cq() that fails to cancel the internal poll work, leading to a use-after-free. An attacker may cause a kernel panic and reboot. The weakness is a classic Use-after-free, exposing the kernel to a denial of service.
Affected Systems
All Linux kernel builds that include the unpatched smbdirect_connection_destroy_qp() path – generally any system that has SMB Direct enabled (often via the af_infiniband and rdma core modules). The issue is present in kernels prior to the commit that introduces ib_free_cq(), so any production server or host running such a kernel is impacted, regardless of distribution vendor.
Risk and Exploitability
The CVSS v3 score of 9.8 denotes critical severity, but the EPSS score of less than 1% implies a low current exploitation probability. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector involves a remote network attacker who can send SMB Direct traffic that triggers late completions, such as a Soft-RoCE provider posting a completion after the queue has been freed.
OpenCVE Enrichment