Impact
In the Linux kernel’s RDMA/rxe driver, the contents of a user‑mode work‑queue entry are copied into the driver’s scatter‑list array without validating the num_sge or cur_sge fields. Since the driver can read beyond the bounds of the array, a malicious value crafted by the user causes an out‑of‑bounds read. The fault does not directly provide control‑flow hijack or privilege escalation, but it can corrupt kernel memory and crash the calling process, leading to a local denial‑of‑service condition.
Affected Systems
Any Linux system that runs a kernel build including the RDMA/rxe driver is potentially affected. Systems that have merged the bound‑check patch or backported it are not impacted. No specific version range is provided in the CNA data, so the vulnerability applies to all kernel releases prior to the patch merge.
Risk and Exploitability
The CVSS score of 7.1 places the flaw in the high‑severity category. The EPSS score is reported as less than 1%, indicating a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local, requiring an unprivileged user with access to post RDMA send requests; no privilege escalation is achieved. Attacking this vulnerability can trigger a kernel OOB read and cause a crash or denial of service for the target process, but the kernel remains stable and an attacker cannot gain further access.
OpenCVE Enrichment
Debian DLA
Debian DSA