CVE-2025-71084

Source
https://cve.org/CVERecord?id=CVE-2025-71084
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71084.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-71084
Downstream
Related
Published
2026-01-13T15:34:47.665Z
Modified
2026-03-12T02:18:45.835687Z
Summary
RDMA/cm: Fix leaking the multicast GID table reference
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/cm: Fix leaking the multicast GID table reference

If the CM ID is destroyed while the CM event for multicast creating is still queued the cancelworksync() will prevent the work from running which also prevents destroying the ah_attr. This leaks a refcount and triggers a WARN:

GID entry ref leak for dev syz1 index 2 ref=573 WARNING: CPU: 1 PID: 655 at drivers/infiniband/core/cache.c:809 releasegidtable drivers/infiniband/core/cache.c:806 [inline] WARNING: CPU: 1 PID: 655 at drivers/infiniband/core/cache.c:809 gidtablerelease_one+0x284/0x3cc drivers/infiniband/core/cache.c:886

Destroy the ah_attr after canceling the work, it is safe to call this twice.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71084.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
60d613b39e8d0c9f3b526e9c96445422b4562d76
Fixed
d5ce588a9552878859a4d44b70b724216c188a5f
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
fe454dc31e84f8c14cb8942fcb61666c9f40745b
Fixed
abf38398724ecc888f62c678d288da40d11878af
Fixed
ab668a58c4a2ccb6d54add7a76f2f955d15d0196
Fixed
c0acdee513239e1d6e1b490f56be0e6837dfd162
Fixed
5cb34bb5fd726491b809efbeb5cfd63ae5bf9cf3
Fixed
3ba6d01c4b3c584264dc733c6a2ecc5bbc8e0bb5
Fixed
57f3cb6c84159d12ba343574df2115fb18dd83ca
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
a3262b3884dd67b4c5632ce7cdf9cff9d1a575d4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71084.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.10.248
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.198
Type
ECOSYSTEM
Events
Introduced
5.12.0
Fixed
6.1.160
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.6.120
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.12.64
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.18.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71084.json"