Impact
The flaw arises when the RDMA SRP driver processes a truncated SRP_CRED_REQ or SRP_AER_REQ packet. The driver forwards a received byte length ("wc->byte_len") to a function that expects a full structure, then reads fixed‑size fields without validating that the packets contain those fields. An attacker can send a request that declares a small size (e.g., 8 bytes) but still contains longer data. The driver then copies data past the end of the allocated buffer and sends the leaked bytes back to the initiator. Each response can expose up to eight bytes of kernel heap memory, potentially revealing pointers or other internal information that could aid further attacks. The vulnerability is purely an information‑leak; it does not provide direct code execution or privilege escalation.
Affected Systems
The issue resides in the Linux kernel’s RDMA/SRP implementation. All kernel releases prior to the back‑ported fix are affected, regardless of distribution. The patch commits listed in the references (starting at 001adf2fe87d1ab6…) contain the defensive changes; any system running a kernel that has not incorporated those commits suffers from the exploitation.
Risk and Exploitability
The EPSS score is reported as less than 1 %, implying a very low probability of widespread exploitation. The vulnerability is not included in the CISA KEV catalog, and no exploit code has been published. Successful exploitation requires an attacker with network access to a host that exposes the SRP RDMA service and the ability to send malformed SRP packets, limiting the threat surface. However, the information disclosed could assist a more advanced attacker in enumerating kernel objects or crafting subsequent attacks. While the immediate risk is moderate, it is non‑negligible for systems with exposed RDMA interfaces.
OpenCVE Enrichment
Debian DLA
Debian DSA