Impact
The bug arises in the RDMA/siw accept routine when a queue pair that is already in the Ready‑To‑Send state is processed. During error cleanup the code mistakenly drops a reference from the incoming Connection Endpoint rather than the existing QP’s endpoint, which can free that endpoint before it is reused. This sequence can trigger a use‑after‑free that corrupts kernel memory and clears an existing queue‑pair association.
Affected Systems
All Linux kernel releases that include the original siw_accept() implementation in the RDMA/siw subsystem. No specific version range is provided, so any kernel containing this code path is at risk until a kernel update that incorporates the fix is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of < 1 % suggests a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an untrusted or compromised userspace process that can initiate RDMA connections to the kernel, exercising the vulnerable code path.
OpenCVE Enrichment
Debian DLA
Debian DSA