Junglewise Threat Intelligence

CVE-2026-46176: Linux kernel mlx5 RDMA use-after-free in mlx5_ib_dev_res_srq_init

CVE-2026-46176 · Severity: info · CVSS 0 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Mellanox (mlx5) network driver that could lead to system instability or crashes. The issue occurs during the initialization of high-performance networking resources, where a failure in one part of the process incorrectly leaves the system in a broken state. This could potentially be exploited by a local user to cause a denial-of-service (system crash) or lead to unpredictable behavior in data center environments using RDMA networking.

Technical details

A vulnerability exists in the mlx5_ib_dev_res_srq_init() function within the Linux kernel's RDMA subsystem. The function allocates two Shared Receive Queues (SRQs), s0 and s1; however, if the allocation of s1 fails, the error handling logic destroys s0 but fails to exit the function. This 'fall-through' results in the freed pointer for s0 and an error pointer for s1 being assigned to the device resource structure. Subsequent operations, such as Queue Pair (QP) creation or driver cleanup, then dereference these invalid pointers, leading to use-after-free, null/error pointer dereference, or double-free scenarios. The fix introduces a proper jump to the unlock/exit label upon s1 allocation failure.

Affected products

  • Linux Linux kernel mlx5 driver component

Timeline

  • 2026-04-24: other: Patch authored
  • 2026-05-28: advisory: NVD publication date

References

Related threats