Impact
In the Linux kernel a use‑after‑free flaw exists in the RDMA core during the freeing of completion queues (CQ). When a CQ is destroyed through the netlink interface, the rdma_restrack_del() function is called too late, after vendor‑specific resources may already have been released. This creates a brief window where the CQ remains reachable via the restrack mechanism, allowing an attacker to use freed memory and potentially trigger kernel crashes.
Affected Systems
All Linux kernel installations that incorporate the RDMA core subsystem and expose the RDMA netlink interface are affected. The vulnerability is present in any kernel where the ib_free_cq() routine is used to deallocate CQs, as the issue originates from the timing of the rdma_restrack_del() call relative to vendor resource cleanup.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the EPSS score of less than 1% shows a very low yet non‑zero probability of exploitation. The vulnerability is not yet listed in the CISA KEV catalog, suggesting the exploitation activity is not broadly observed. The likely attack vector is a local privileged attacker with access to the RDMA netlink interface; remote exploitation would require additional compromises. Given the low EPSS and absence from KEV, the overall risk, while significant if exploited, is considered moderate compared to the high severity score.
OpenCVE Enrichment
Debian DLA
Debian DSA