Impact
A flaw in the Linux kernel RDMA/rxe driver causes a query path to re‑process a packet that is already marked for completion when the Queue Pair (QP) enters an error state. The driver ends up posting the same successful completion to the completion queue repeatedly, and when the work queue becomes empty a NULL pointer dereference occurs, causing a kernel panic. The duplicate completions also lead to the same payload being delivered to user space multiple times, corrupting streams for protocols that assume one‑to‑one delivery.
Affected Systems
All Linux kernels that contain the RDMA/rxe driver are affected; the issue exists in the current release series erroneous error‑state branch is applied. No specific version list is provided, so any kernel containing the vulnerable code path is considered at risk.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity. The EPSS score is below 1 %, meaning it is unlikely to be actively exploited at present, and it is not listed in the CISA KEV catalog. The vulnerability is exploitable through RDMA traffic sent to the target system; a malicious remote party can trigger the kernel crash by causing a QP to transit to the error state while a packet is being processed. The impact is primarily a denial‑of‑service via kernel crash, with secondary data corruption for applications that rely on exactly‑once delivery.
OpenCVE Enrichment
Debian DLA
Debian DSA