GPU VulnDB

Database/Firmware, BMC & network fabric

Linux kernel (drivers/infiniband/hw/erdma): Use-after-free while accepting an inbound RDMA connection. The connection

CVE-2025-22088Firmware, BMC & network fabriccurated

Impact

Use-after-free while accepting an inbound RDMA connection. The connection endpoint is dropped and then dereferenced again inside the accept path, so a peer opening connections against a listener reaches freed kernel memory. Rated critical and network-reachable by the kernel CNA.

Who can reach it

Pre-authentication and fully remote: any peer that can reach an erdma listener drives the accept path - no host account, no device node, no tenant cooperation. Requires the erdma driver (Alibaba Cloud elastic RDMA), so this matters if any part of the fleet runs on Alibaba Cloud instances with RDMA enabled.

What to do

No fixed release is published in this record - apply the listed stable fix commits or run a current stable kernel image for those instances. Interim: restrict which sources can reach erdma listeners (security groups / firewall), or unload erdma on hosts that do not use it.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.