Impact
The vulnerability is a use‑after‑free in the Linux kernel’s RDMA core, specifically the ib_dealloc_pd_user() routine. When a protection domain (PD) is deallocated, the system removes the PD from reference tracking only after its internal resources are freed, leaving a short window where the PD remains reachable. This can allow an attacker to access freed memory. Based on the description, it is inferred that such access could lead to kernel‑level memory corruption, a potential crash, or even arbitrary code execution if the attacker can manipulate the freed space.
Affected Systems
Linux kernel implementations that expose the RDMA core and have not incorporated the patch at commit 66d65f36d39759e9f62dc746dc71d862f20f827f. Any kernel build before this commit, which includes the ib_dealloc_pd_user() routine without the early restrack removal, is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 7.8 indicates high severity, but the EPSS score of < 1% suggests that exploitation is unlikely to be common. The vulnerability is not listed in CISA's KEV catalog, further indicating limited known exploitation. The attack surface is local or system‑level, requiring interaction with the RDMA netlink interface or administrative RDMA operations. Systems that allow privileged RDMA administration without strict access controls face higher risk, while those that restrict RDMA access remain less exposed.
OpenCVE Enrichment
Debian DLA
Debian DSA