Impact
The bug occurs when a Shared Receive Queue (SRQ) is destroyed in the RDMA core driver. The destruction routine invokes a clean‑up function too late, after vendor‑specific resources have already been freed, leaving the SRQ still referenced by the restrack mechanism. An attacker that can initiate a netlink request to access an SRQ may use the remaining reference to trigger a use‑after‑free, potentially corrupting kernel memory or causing a crash. The underlying weakness is a classic use‑after‑free error (CWE‑416).
Affected Systems
The vulnerability applies to all Linux kernel builds that contain the unpatched ib_destroy_srq_user function. The impacted vendors are represented by the Linux upstream kernel project. No specific version range was supplied, so any kernel that shipped before the patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 classifies this as a high severity issue. The EPSS score of less than 1% indicates a very low probability of active exploitation, and the vulnerability is currently not listed in the CISA KEV catalog. The attack requires administrative or kernel‑space privileges to send a netlink command that references a user‑mode SRQ (inferred), making the exploitation path limited to privileged users or compromised applications with RDMA access. Nonetheless, the combination of a use‑after‑free and privileged netlink access (inferred) gives an attacker the potential to corrupt memory or crash the kernel, which could be leveraged for privilege escalation or denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA