Impact
The vulnerability is in the Linux kernel RDMA erdma subsystem. When destroy commands for queue pairs, completion queues, memory registrations or address handles fail—typically after a command timeout—the routine returns success but does not free the software‑owned queue buffers, MTTs, doorbells, or the identifiers (STAG, QPN, CQN, AHN). This leaves those resources allocated and unreachable, causing a leak that can grow without bound and eventually exhaust system resources or the RDMA identifier pool, impairing functionality. It is inferred that the leaked resources persist until a system reboot or driver reload, as the erdma core keeps the object after a failed destructor and then sets pointers to null.
Affected Systems
All Linux kernel builds that include the erdma RDMA driver. Any system running a Linux kernel with RDMA/erdma support—such as servers, HPC nodes, or embedded platforms that compile erdma into the kernel—will be affected. The patch release notes do not provide specific version ranges, so all current releases prior to the fix should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.0 indicates high severity. The EPSS score is less than 1%, indicating a very low current exploitation probability. The vulnerability is not in CISA KEV. Attackers would need to invoke erdma_destroy* calls that fail; the description does not directly state the required privilege level, but based on the need to perform RDMA driver operations, it is inferred that local or privileged access is required. This inference is not proven in the description. A failure causes kernel resources to be leaked, potentially leading to exhaustion and local denial of service. There is no indication that the flaw is exploitable remotely, so remote exploitation is unlikely without additional vulnerabilities.
OpenCVE Enrichment
Debian DLA
Debian DSA