Impact
A use‑after‑free bug exists in the Linux kernel’s RDMA core when handling netlink QP queries. The flaw arises because the RDMA restriction tracker is only removed after the vendor‑specific resources are freed, leaving the QP structure still reachable. An attacker can exploit this race to trigger a use‑after‑free in the ib_query_qp function, which may corrupt kernel memory or cause a crash. This vulnerability has the potential to compromise system integrity and could be escalated to arbitrary code execution if the memory corruption can be directed.
Affected Systems
The flaw is present in all publicly released Linux kernel sources that include the RDMA core, i.e., standard Linux kernels prior to the fixed commit. It affects the Linux kernel vendor and their downstream distributions that ship the unpatched code. No specific version numbers are given, so any kernel older than the patch may be vulnerable.
Risk and Exploitability
The EPSS score is reported as less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting a very low exploitation probability in the wild. However, the function can be triggered via netlink, which typically requires CAP_NET_ADMIN or another privileged capability. Local privileged users or processes that can send netlink messages to the RDMA subsystem are therefore the most likely attack vectors. In the absence of a published public exploit, the risk remains theoretical but should be mitigated promptly due to the severity of a kernel memory corruption.
OpenCVE Enrichment
Debian DLA
Debian DSA