Impact
The Linux kernel’s nvmet‑rdma subsystem leaks memory when an NVMe target that uses RDMA transport is removed while I/O operations are still in flight. An outstanding response is posted but its send completion never reaches the kernel before the RDMA queue pair is torn down. Consequently the kernel fails to invoke nvmet_rdma_send_release_rsp(), leaving the allocated RDMA read/write context and request SGLs unreleased. The leak involves small 32‑64 byte objects but can accumulate across many in‑flight requests, eventually exhausting kernel memory, degrading performance or causing the system to crash. The CVE identifies and fixes this fault by calling nvmet_rdma_free_rsp_resources() to reclaim the resources.
Affected Systems
Any Linux installation that builds its kernel with the nvmet‑rdma module and enables RDMA transport is affected. This includes all distributions shipping the default Linux kernel with nvmet support that have not yet incorporated the upstream commit adding the resource reclamation. The vulnerability applies regardless of kernel version until the patch is applied.
Risk and Exploitability
The CVSS score of 7.5 classifies the bug as high severity, while the EPSS score of less than 1% indicates a very low likelihood of real‑world exploitation at this time. The vulnerability is not in the CISA KEV catalog. Attackers would need the ability to issue NVMe I/O requests to a target that uses RDMA and then trigger removal of the target or its RDMA queue pair while operations remain queued. This could be achieved locally by a privileged user or, in a networked environment, remotely if the NVMe target is exposed. Successful exploitation results in a sustained memory leak that could culminate in a denial‑of‑service condition through kernel memory exhaustion.
OpenCVE Enrichment
Debian DLA
Debian DSA