Impact
The vulnerability stems from a short window in the Linux kernel’s RDMA core module where a counter remains registered in the restrack mechanism after its vendor‑specific resources have been freed. During this period the counter can still be accessed through the netlink interface, creating a use‑after‑free condition that could corrupt kernel memory or cause a crash. The weakness is a classic memory safety issue that directly jeopardizes kernel integrity.
Affected Systems
All Linux kernel deployments that include the RDMA core component. No specific version ranges are provided, so any kernel tree containing the affected code before the patch may be vulnerable.
Risk and Exploitability
Based on the description, the flaw arises when a counter is still accessible after its internal resources have been released, creating a use‑after‑free opportunity. The EPSS score of <1% and the absence of the vulnerability in the CISA KEV list suggest a very low probability of exploitation and no known active attacks. The likely attack vector, inferred from the use of a netlink‑based counter interface, would involve an attacker with sufficient privileges on the host to interact with the RDMA subsystem. However, the description does not confirm that remote or unprivileged access is possible, so the exact scope remains uncertain. Because the flaw is not presently exploited and requires privileged local interaction, the overall risk can be considered low until remediation is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA