CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's svcrdma component, where improper memory management during listener creation failures can lead to resource leaks and potential denial of service. Specifically, the misuse of memory deallocation functions bypasses necessary cleanup routines, which could destabilize the system if not addressed. Linux system administrators and developers working with RDMA (Remote Direct Memory Access) services should prioritize this issue to ensure system stability and resource management.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Use svc_xprt_put to free listener on create failure svc_rdma_create() calls kfree(cma_xprt) when svc_rdma_create_listen_id() fails. svc_xprt_init() has already acquired a net namespace reference via get_net_track(); kfree bypasses svc_xprt_free() which releases it. Replace the kfree() with svc_xprt_put() so the kref_init birth reference drops to zero and svc_xprt_free() dispatches svc_rdma_free() to clean up properly. sc_cm_id is still NULL at that point; the preceding patch added the necessary NULL guard in svc_rdma_free(). svc_xprt_free() also drops the module reference via module_put(), but the caller _svc_xprt_create() does the same on xpo_create failure, double-putting the single try_module_get() it acquired. Take a compensating __module_get() before the svc_xprt_put() to keep the count balanced, matching the convention in svc_rdma_accept()'s error path.