Impact
A flaw in the RDMA/irdma subsystem of the Linux kernel allowed a userspace process to deregister memory regions that were still referenced by kernel RDMA rings, potentially causing the kernel to free memory in use and later access it again. Such an error can lead to a kernel crash, disrupting service availability. The patch that added refcounting prevents this race condition.
Affected Systems
All Linux kernel builds that include the irdma driver and have not applied commit 07974c267f603a76aead348bca97deee95efdcc9 are potentially affected. No specific kernel versions are listed, so any distribution shipping an unpatched kernel with irdma support is at risk.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates that, at present, organized exploitation appears unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need local access to a process interacting with RDMA devices to trigger the race, which is considered an inference based on the information available. The patch removes the risk by enforcing a reference count on memory regions that back RDMA rings.
OpenCVE Enrichment