Executive brief
The Linux kernel's RDMA/erdma driver fails to properly clean up system resources (memory buffers, device identifiers) when destruction commands for queue pairs, completion queues, memory regions, and address handles encounter timeouts or errors. This leads to permanent resource leaks that exhaust system resources and degrade availability. An attacker with local access to trigger repeated destruction failures could cause denial of service.
Technical details
The vulnerability is a resource leak in the RDMA/erdma driver's destroy path (erdma_destroy_qp, erdma_destroy_cq, erdma_dereg_mr, erdma_destroy_ah functions). When erdma_post_cmd_wait() fails—particularly due to command queue timeout, which permanently disables ERDMA_CMDQ_STATE_OK_BIT—the functions returned early without releasing queue buffers, memory translation table entries (MTTs), doorbells, and resource identifiers (STAG, QPN, CQN, AHN). Since a timeout disables the command queue permanently, the RDMA core framework retains the parent object with nulled pointers, making the leaked resources unreachable. The fix changes these destroy functions to log a warning on command failure but proceed with software resource cleanup and return success, treating hardware errors as diagnostic-only during terminal destruction. This affects all Linux kernel versions since the erdma verbs implementation was added.
Affected products
- Linux Linux kernel all versions since RDMA/erdma verbs implementation (commit 155055771704)
Timeline
- 2026-09-17: disclosed
- 2026-09-14: patched: fix committed upstream