Impact
The kernel bug in mana_table_store_ud_qp publishes a QP reference before fully inserting the receive queue entry and releases the XArray lock between the two xa_insert_irq calls. A completion handler running concurrently can acquire a transient reference to the QP while the second insertion fails and only rolls back the first entry. This leaves both the initial table reference and the transient reference outstanding. When RDMA core later frees the QP, the stale references trigger a use‑after‑free, permitting an attacker to execute code in kernel mode or crash the system. The flaw is a classic use‑after‑free condition (CWE‑416) and carries the potential for arbitrary code execution or denial of service.
Affected Systems
All Linux kernel builds that include the RDMA/mana_ib driver before the patch that removes the race between the two xa_insert_irq calls are affected. The vulnerability does not involve a specific kernel version in the data provided, so any kernel that has not yet incorporated the referenced commit is at risk.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low exploitation probability in the wild. However, the flaw grants kernel‑level persistence and the affectation of RDMA core implies a high CVSS severity potential. Attack vectors would involve initiating RDMA operations that trigger the partial insertion race, which requires local access to RDMA resources but may be feasible for privileged users or within compromised workloads. Because the issue requires concurrent operation, exploitation might be harder to achieve, aligning with the low EPSS score, but it remains a high‑risk flaw due to the privilege level it can compromise.
OpenCVE Enrichment