Impact
The RDMA/ipoib driver in the Linux kernel contains a flaw that permits a callback scheduled under the RCU synchronization mechanism to be executed while the module is still unloading. When the kernel wakes before the callback completes, the driver may reference memory that it has already been freed, leading to a use‑after‑free situation that can result in a kernel crash or, in the worst case, arbitrary code execution as part of the kernel.
Affected Systems
All Linux kernel releases that include the RDMA/ipoib driver are potentially affected; the exact affected versions are not specified in the CVE data, so the issue should be considered for all kernels that have not applied the relevant patch from the kernel maintainers.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation, but the vulnerability is not currently listed in the CISA KEV catalog. The CVSS score is not provided, however the nature of the flaw—use‑after‑free in the kernel—implies a high impact score if exploited. A local privileged attacker can trigger the flaw by unloading the module while an RCU callback is pending, potentially causing a denial of service or execution of arbitrary code. The attack vector is inferred as local, requiring the ability to unload kernel modules or interfere with RDMA operations.
OpenCVE Enrichment
Debian DLA
Debian DSA