Junglewise Threat Intelligence

CVE-2026-46144: Linux RDMA/mana resource leak in mana_ib_create_qp_rss

CVE-2026-46144 · Severity: info · CVSS 0 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A resource management issue was identified in the Linux kernel's Microsoft Azure Network Adapter (MANA) driver. When the system fails to create certain network queue structures, it may fail to properly release previously allocated resources. This could lead to a gradual depletion of system resources, potentially impacting the stability of virtual machines running on Azure that utilize high-performance networking.

Technical details

A resource leak exists in the mana_ib_create_qp_rss() function within the RDMA/mana driver of the Linux kernel. The vulnerability is caused by an incomplete error handling path (unwind) where a failure in copying data to userspace (udata) does not trigger the necessary cleanup for vport steering configurations. Specifically, mana_ib_cfg_vport_steering() is leaked because the code jumps to a generic failure label that misses the mana_disable_vport_rx() call. This is a local resource leak that can be triggered during failed Queue Pair (QP) creation for Receive Side Scaling (RSS). The issue has been resolved by adding the appropriate error label and cleanup call in the driver's QP management logic.

Affected products

  • Linux Linux kernel Fixed in 190e570cc0fc7f57eacf80d2b854ba54b4dfad6b, 30e8a2f33815d8f51b8f8b829c07af16c671cc27, 6aaa978c6b6218cfac15fe1dab17c76fe229ce3f, 726af85ea4af750b2f75095e24e3cd99797344cb, ab64c63b460bbd0521480bf90d5695783f5e66bc

Timeline

  • 2026-05-28: advisory: NVD publication date
  • 2026-05-02: patched: Initial fix commit by Jason Gunthorpe

References

Related threats