Junglewise Threat Intelligence

CVE-2022-50666: Linux kernel RDMA/siw use-after-free in QP destroy

CVE-2022-50666 · Severity: critical · CVSS 9.8 · Published 2025-12-09

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RDMA software iWARP (siw) driver had a use-after-free vulnerability in its queue pair (QP) destruction logic. After a QP was destroyed, pending work handlers could still reference the freed memory, causing kernel memory corruption. This could lead to system crashes or potential code execution when exploited by local attackers with network access to trigger connection drops.

Technical details

The vulnerability is a use-after-free in the siw_destroy_qp() function in the RDMA iWARP software driver. When a QP is destroyed, the RDMA core immediately frees the QP structure after siw_qp_destroy() returns, but pending siw_cm_work_handler callbacks could still hold references and access the freed QP. The root cause was that QP destruction did not wait for all in-flight work handlers to complete before returning. The fix introduces a completion synchronization primitive (qp_free) that is waited on during destruction and signaled only after all references are dropped. The vulnerability requires a local or network-adjacent attacker to trigger connection drops during NFSoRDMA or similar workloads. A patch was applied upstream (commit a3c278807a459e6f50afee6971cabe74cccfb490) and backported to stable kernel branches.

Affected products

  • Linux Linux kernel 5.0 through 5.19, 6.0 and later (prior to patch)

Timeline

  • 2022-09-20: disclosed: Patch authored by Bernard Metzler
  • 2022-10-21: patched: Patch committed to stable kernel; backported to multiple stable branches
  • 2025-12-09: other: Advisory published

References

Related threats