Executive brief
A vulnerability was identified in the Linux kernel's RDMA driver for HiSilicon network hardware. This flaw could allow a local user to cause a system crash or potentially execute unauthorized actions due to improper memory management during error handling. This affects the stability and reliability of servers using specific high-performance networking hardware.
Technical details
A double-free vulnerability (CWE-415) exists in the RDMA/hns driver within the Linux kernel. The root cause is the double destruction of the 'rsv_qp' object during an error flow: it is first destroyed in free_mr_init() and subsequently in hns_roce_exit(). This leads to list_del corruption and kernel warnings (LIST_POISON1). An attacker with local access could exploit this to cause a Denial of Service (kernel panic) or potentially achieve privilege escalation. The fix involves moving the free_mr_init() call into hns_roce_v2_init() to ensure proper resource lifecycle management. Patches have been released for various stable kernel branches including 6.1.y, 6.6.y, 6.10.y, and 6.11.y.
Affected products
- Linux Linux Kernel 6.1.113, 6.6.54, 6.10.13, 6.11.2, 6.12
Timeline
- 2025-08-19: advisory: CVE-2025-38582 published by NVD
- 2025-08-15: patched: Patched in Linux stable tree by Greg Kroah-Hartman