Executive brief
The Linux kernel's RDMA/efa driver incorrectly deallocates resources when destroying queue pairs (QP) or completion queues (CQ). If device destruction fails, a caller can retry the destruction operation, leading to a reference count underflow and potential memory corruption. This could cause system crashes or be leveraged as part of a denial-of-service attack on systems using RDMA networking.
Technical details
The vulnerability is a use-after-free / double-free condition in the RDMA EFA (Elastic Fabric Adapter) driver's QP and CQ destruction paths. The vulnerable code decrements reference counts and deallocates memory regions before requesting the device to destroy the object. If device destruction fails, the partial state allows a caller to retry destruction, causing refcount underflow on already-freed objects. The fix reorders deallocation to occur after successful device destruction, ensuring resources are only freed once. The vulnerability affects Linux kernel versions with the RDMA/efa driver; exploitation requires network access or local access to RDMA operations.
Affected products
- Linux Linux kernel versions with RDMA/efa driver support (approximately 5.2 and later)
Timeline
- 2023-08-22: disclosed
- 2023-09-13: patched
- 2025-12-30: advisory