CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's RDMA (Remote Direct Memory Access) subsystem, specifically in the handling of address change events within the svc_rdma_listen_handler() function. If a replacement listener fails to allocate, the existing connection identifier (cm_id) may be dereferenced after being freed, leading to a potential use-after-free condition. Organizations utilizing Linux systems with RDMA capabilities should prioritize addressing this issue to mitigate risks associated with memory corruption and potential system instability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails When svc_rdma_listen_handler() handles RDMA_CM_EVENT_ADDR_CHANGE, it creates a replacement listener cm_id and returns 1, telling the CM core to destroy the old one. If the replacement allocation fails, sc_cm_id still points at the old cm_id that the CM core is about to destroy. Any subsequent dereference of sc_cm_id -- such as svc_rdma_detach()'s rdma_disconnect() call -- is a use-after-free. NULL sc_cm_id on the failure path and guard svc_rdma_detach()'s rdma_disconnect() call against NULL so that the listener can be torn down safely when the server shuts down.