Impact
The Linux kernel RDMA/erdma subsystem contains a race condition that allows a process to remove a Queue Pair (QP) while another part of the code still holds a reference to it. The likely attack vector involves an attacker sending specially crafted RDMA operations to trigger simultaneous removal and lookup of a QP. During an AE QP fatal event or an iWARP Connection Manager path, the subsystem looks up QPs from a table outside the protection of the xarray lock; if erdma_destroy_qp() frees the QP concurrently, a use-after-free can occur. Based on the description, the flaw is only exploitable when a QP is destroyed concurrently with an AE event or CM path. This flaw could let an attacker manipulating RDMA operations trigger a crash or potentially corrupt memory, compromising the integrity of the kernel.
Affected Systems
The vulnerability affects the Linux kernel, specifically the RDMA/erdma component. No specific kernel versions are listed, implying that all versions vulnerable to the original bug are at risk until the patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate to high severity, but the EPSS score of less than 1% suggests that the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local or network-based adversary with the ability to issue RDMA/erDMA commands on the affected system. Exploitation would require an attacker to manipulate the QP lifecycle during AE events or CM paths, allowing a use-after-free that could lead to a denial of service or memory corruption.
OpenCVE Enrichment
Debian DLA
Debian DSA