Executive brief
A resource leak was identified in the Linux kernel's RDMA driver for Mellanox ConnectX adapters. This component is responsible for high-speed data transfers between servers. If an error occurs during the creation of a shared receive queue, the system fails to release allocated memory, which could lead to gradual performance degradation or system instability over time.
Technical details
A resource leak exists in the mlx4_ib_create_srq() function within the drivers/infiniband/hw/mlx4/srq.c file of the Linux kernel. The vulnerability occurs because the mlx4_srq_alloc() operation was not properly undone during the error unwind path when ib_copy_to_udata() fails. An attacker with local access could potentially trigger this error path repeatedly to exhaust kernel resources. The fix introduces a missing call to mlx4_srq_free() in the error handling logic. Patches have been backported to various stable kernel branches.
Affected products
- Linux Linux Kernel All versions prior to the May 2026 patches
Timeline
- 2026-04-28: other: Patch authored by Jason Gunthorpe
- 2026-05-28: disclosed: CVE published in NVD dataset
References
- https://git.kernel.org/stable/c/0dbd619716fb07b7de1acd64fec673ee6e1adde7
- https://git.kernel.org/stable/c/388617f44d81604a760742a0b5de292d411e63e3
- https://git.kernel.org/stable/c/c54c7e4cb679c0aaa1cb489b9c3f2cd98e63a44c
- https://git.kernel.org/stable/c/c5dc30da990045105c9762248d23076223e7878a
- https://git.kernel.org/stable/c/e01b8c9286c470b71a38acd320106f2c4f2826a1