Impact
The Linux kernel’s RDMA core contains a flaw in the cleanup of a completion queue (CQ). The code removes the CQ from the restrack list only after vendor‑specific resources have already been freed, creating a brief window where the CQ remains reachable through restrack while its internal memory is no longer valid, leading to a use‑after‑free. The CVE description does not specify the potential impact of the use‑after‑free beyond the possibility of accessing freed memory.
Affected Systems
The vulnerability affects all builds of the Linux kernel that lack the commit moving rdma_restrack_begin_del() to the start of ib_destroy_cq_user(). The affected vendor is Linux and the product is the Linux kernel. No explicit version range is provided, so any kernel before the patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is below 1 %, suggesting exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The flaw is exposed when a CQ is accessed via the netlink interface, but the CVE description does not specify the required privilege level. No public exploits are known.
OpenCVE Enrichment
Debian DLA
Debian DSA