Impact
During RDMA rvt device allocation, when the port array cannot be allocated, the function frees the allocated device but returns the pointer to the released memory. Callers treat any non-NULL value as a valid device pointer, causing a use-after-free that can corrupt memory, crash the system, or provide arbitrary code execution if an attacker can influence the deallocation path. The bug is contained in the Linux kernel’s RDMA rvt subsystem.
Affected Systems
The flaw affects the Linux kernel’s RDMA rvt subsystem. All kernel releases that include the unpatched rvt_alloc_device() implementation are vulnerable until a patch is applied; the vendor has not published a specific version range in the advisory.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Because the issue is a classic use‑after‑free, the impact is severe. Based on the description, it is inferred that an attacker would need to trigger the allocation failure path, likely requiring local or higher privileges to reach the vulnerable code.
OpenCVE Enrichment