Impact
The vulnerability occurs when the erdma CEQ interrupt handler schedules a tasklet that later accesses DMA‑coherent memory that has been freed during CEQ removal. This use‑after‑free leads to a memory corruption in the kernel, potentially triggering a panic or crash. The weakness is a classic memory‑corruption flaw, consistently classified as CWE‑416.
Affected Systems
The flaw attacks the Linux kernel RDMA/erdma driver. Any system that loads the erdma module and runs a kernel version before the referenced commit fixes is susceptible. No specific release dates are provided, so all current kernels that have not yet incorporated the patch are at risk.
Risk and Exploitability
The EPSS score indicates a very low exploitation probability (<1 %), and the vulnerability is not listed in the CISA KEV catalog. A CVSS score has not been disclosed. Exploitation requires initiating a CEQ removal, which typically demands privileged kernel access; this requirement is inferred from the nature of the operation but is not explicitly stated in the advisory.
OpenCVE Enrichment
Debian DLA
Debian DSA