CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's RDMA subsystem, specifically in the srpt_alloc_rw_ctxs() function, which improperly handles error conditions during multi-buffer indirect descriptor allocation. This flaw can lead to incorrect accounting of send queue credits, potentially allowing an attacker to exploit the system's resources or disrupt RDMA operations. Organizations using Linux systems with RDMA capabilities should prioritize patching this critical vulnerability to mitigate the risk of resource exhaustion and potential denial-of-service attacks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later sq_wr_avail accounting in srpt_queue_response() or srpt_write_pending() can then subtract the wrong number of send queue credits. Reset the counters and clear rw_ctxs after freeing the heap allocation before returning an error.
Related CVEs
Other vulnerabilities affecting the same vendor(s)