Impact
The vulnerability arises from improper handling of a socket buffer in the Linux‑kernel RDMA cxgb4 driver during error conditions. When the device enters a fatal error state, the write_tpt_entry() function returns an error before handing off the preallocated skb to the transmit path, causing a memory leak. Additionally, a double free occurs when c4iw_get_dma_mr() frees the same skb after dereg_mem() has already consumed it. Both a memory leak and a double free can corrupt kernel memory or exhaust resources, resulting in system instability, crashes, or a denial of service.
Affected Systems
Linux kernel, cxgb4 RDMA driver. No specific version information is supplied; any kernel build that includes the affected code path is potentially impacted.
Risk and Exploitability
The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The CVSS score is not provided, so the severity cannot be determined from the available data. Exploitation would likely require local access to interact with the RDMA subsystem, making it a local denial-of-service risk. No active exploit is known.
OpenCVE Enrichment