Impact
The vulnerability lies in the RDMA mlx5 driver, where the devx_free_subscription() callback can remain queued after the last reference to the module is released or an auxiliary driver detaches its devices. When the mlx5_ib driver unloads before that callback runs, the callback executes on a no‑longer‑existent module, creating a use‑after‑free condition. This flaw enables a race condition that could lead to crashes, kernel panic, or other disruptive failures, impacting the availability of the affected system.
Affected Systems
All Linux kernel builds that contain the RDMA mlx5 driver are affected. The exact versions are not specified in the public data, so any kernel that ships the mlx5 module without an applied patch is at risk. Devices that rely on devx or aml_driver interfaces are potentially sensitive if the driver is unloaded while still in use.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low likelihood of exploitation in the wild, and no alerts exist in the CISA KEV catalog. However, the flaw remains a severe race condition. Based on the description, it is inferred that an attacker with local or privileged access who can trigger module unloading or manipulate RDMA events could exploit the race to destabilize the system. Current best practice is to treat this as a high‑severity issue that warrants patching at the earliest opportunity.
OpenCVE Enrichment
Debian DLA
Debian DSA