Impact
The kernel RDMA/rxe subsystem contains a use‑after‑free bug where the memory region pointer is stored before page initialization and not cleared on failure. If the page initialization fails, cleanup code later releases the already‑freed resource again, allowing the kernel to read freed memory and corrupt data. This flaw is a classic Use‑After‑Free condition and can cause unexpected kernel behavior or a crash.
Affected Systems
The vulnerability affects the Linux kernel, specifically the RDMA/rxe driver. No specific kernel releases or version ranges are listed in the information, so any kernel that includes this code path without the patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS is below 1%, suggesting a low probability of current exploitation. The flaw is not listed in CISA’s KEV catalog. Attackers would likely need local or elevated privileges to load code that exploits this kernel bug, but a successful exploit could crash the system or enable memory corruption. The attack vector is therefore inferred to be a local kernel exploitation scenario rather than a remote network attack.
OpenCVE Enrichment