Junglewise Threat Intelligence

CVE-2026-46178: Linux Kernel RDMA/mlx4 resource leak in mlx4_ib_create_srq

CVE-2026-46178 · Severity: info · CVSS 2.1 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A resource leak was identified in the Linux kernel's RDMA driver for Mellanox ConnectX adapters. This component is responsible for high-speed data transfers between servers. If an error occurs during the creation of a shared receive queue, the system fails to release allocated memory, which could lead to gradual performance degradation or system instability over time.

Technical details

A resource leak exists in the mlx4_ib_create_srq() function within the drivers/infiniband/hw/mlx4/srq.c file of the Linux kernel. The vulnerability occurs because the mlx4_srq_alloc() operation was not properly undone during the error unwind path when ib_copy_to_udata() fails. An attacker with local access could potentially trigger this error path repeatedly to exhaust kernel resources. The fix introduces a missing call to mlx4_srq_free() in the error handling logic. Patches have been backported to various stable kernel branches.

Affected products

  • Linux Linux Kernel All versions prior to the May 2026 patches

Timeline

  • 2026-04-28: other: Patch authored by Jason Gunthorpe
  • 2026-05-28: disclosed: CVE published in NVD dataset

References