Impact
The RDMA/hfi1 driver in the Linux kernel does not release allocated RX support structures when initialization fails, causing a memory leak of netdev_rx and a dummy netdev. This unchecked resource consumption can lead to memory exhaustion, potentially causing a denial of service if the system runs out of available memory. The weakness corresponds to an improper release of resources (CWE-401).
Affected Systems
This flaw affects any Linux distribution that includes the RDMA/hfi1 driver in the kernel. Versions prior to the commit that adds a call to hfi1_free_rx() during error cleanup are vulnerable; affected kernel releases are unspecified in the advisory.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The attack vector is likely local, requiring privileged access to load or initialize the RDMA/hfi1 driver, so it is not remotely exploitable. Nonetheless, an adversary with system access could intentionally trigger repeated probe failures to exhaust memory and degrade availability.
OpenCVE Enrichment
Debian DLA
Debian DSA