Executive brief
A vulnerability in the Microsoft Azure Network Adapter (MANA) driver for the Linux kernel could lead to system instability or network errors. When certain network connections are closed, the system fails to properly clear old routing instructions, which can cause incoming network traffic to be misdirected to the wrong internal queues. This could result in kernel warnings or service disruptions when the network interface is restarted.
Technical details
A vulnerability exists in the mana_ib_destroy_qp_rss() function within the Microsoft Azure Network Adapter (MANA) InfiniBand driver. When an RSS Queue Pair (QP) is destroyed, the driver fails to disable vPort RX steering in the firmware, leaving stale steering configurations pointing to destroyed Receive Work Queue (RX WQ) objects. If traffic continues to arrive, the firmware may deliver completions using stale Completion Queue (CQ) IDs. These IDs can be reused by the ethernet driver for new Transmit (TX) CQs, causing RX completions to erroneously land on TX CQs, triggering kernel warnings (e.g., mana_poll_tx_cq). The fix involves refactoring the steering disable logic into a shared function and ensuring it is called before RX WQ objects are destroyed.
Affected products
- Linux Linux kernel 6.2 to 6.8.x
Timeline
- 2026-03-25: patched: Initial patch submitted by Long Li
- 2026-05-27: disclosed: CVE published by kernel.org
References
- https://git.kernel.org/stable/c/3be5ed233de03b00ae868cfc06e95331d8d9007c
- https://git.kernel.org/stable/c/6a2d6273b6c3581ce7b90ce17b5cbb4efd19438f
- https://git.kernel.org/stable/c/8ba804869382ce307f2a15f5f6f2adfd791f41dc
- https://git.kernel.org/stable/c/dbeb256e8dd87233d891b170c0b32a6466467036
- https://git.kernel.org/stable/c/f1ccc4d500a0b87a5599343fc2f798048836e184