Impact
The kernel routine responsible for allocating debugging filesystem entries for RDMA devices fails to clean up those entries if the device registration itself fails. As a result, debugfs dentries accumulate and persist even after the underlying device structure is freed. Over time this leak can consume kernel memory and debugfs space, potentially triggering out-of-memory conditions or forcing the kernel to purge the debugfs hierarchy, which can lead to instability or a denial of service for applications relying on RDMA communication.
Affected Systems
All Linux kernel implementations that include the cxgb4 (c4iw) driver before the patch are affected. The vulnerability is present in any distribution using a kernel version that was released prior to the commit that moved debugfs_remove_recursive() into the deallocation path. The vendor is the Linux Foundation, and the CPE for the affected product is cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*.
Risk and Exploitability
The EPSS score is reported as < 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further suggesting it has not been observed in large‑scale attacks. Exploitation would likely require repeated failures of RDMA device registration, which is usually a local, privileged operation. Because the attack does not provide remote code execution, the risk is mainly a local or compromised system denial of service through resource exhaustion.
OpenCVE Enrichment
Debian DLA
Debian DSA