Impact
The vulnerability occurs in the Linux kernel’s RDMA/erdma subsystem where an EQ handler may invoke callbacks on a Completion Queue that has already been destroyed and freed. The CQ is removed from the xarray and its resources released while an EQ handler still holds a reference to it, creating a classic use‑after‑free scenario. If an attacker can trigger RMDA events that cause the handler to run during or after the free, kernel memory can be corrupted or arbitrary code can be executed with kernel privileges.
Affected Systems
All Linux kernel builds that include the RDMA/erdma driver, and that have not yet applied the fix, are potentially affected. No specific version range is given in the data, so the impact applies broadly to any kernel that ships the unpatched driver code.
Risk and Exploitability
The CVSS score of 7.8 classifies flaw as high severity, while the EPSS score of less than 1% indicates a low probability of current exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, so no widespread confirmed exploitation has been reported. Based on the description, the likely attack vector is local, requiring that an adversary can trigger RDMA events or otherwise interact with the RDMA driver on the affected system. There is no clear public-facing network exploitation path reported.
OpenCVE Enrichment
Debian DLA
Debian DSA