Impact
In the Linux kernel, a bug in the RDMA core stack allows a pending RCU callback to be invoked after the ib_core module has already been unloaded. The callback is queued with call_rcu() from put_gid_ndev() and the module unload sequence does not wait for these callbacks to finish. If the callback executes after the module’s code has been removed, it results in a use‑after‑free that can crash the kernel, leading to a denial of service. This issue is closely related to CWE‑416: Use After Free.
Affected Systems
The vulnerability affects any Linux kernel that includes the ib_core module, typically found in kernel releases that support InfiniBand RDMA networking. The specific affected versions are not enumerated in the public data, so any kernel configured with ib_core remains at risk until updated.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation at present. However, the severity is high if an attacker can unload the ib_core module or force the module to be unloaded in a running system, potentially causing a kernel crash. The primary attack vector is an action that unloads or reloads the module; acquiring module unload privileges is required to realize the exploit.
OpenCVE Enrichment
Debian DLA
Debian DSA