Executive brief
A vulnerability was identified in the Linux kernel's RDMA driver for HiSilicon hardware. Under specific conditions involving network file system (SUNRPC) resets, the system may encounter a kernel warning or potential deadlock during memory reclamation. This could lead to system instability or a denial of service for applications relying on high-performance RDMA networking.
Technical details
A dependency violation was discovered in the hns_roce_hw_v2 driver where a workqueue (hns_roce_irq_workq) lacked the WQ_MEM_RECLAIM flag. When SUNRPC triggers a reset, the xprtiod workqueue (which has WQ_MEM_RECLAIM) attempts to flush hns_roce_irq_workq. Because the latter is not marked for memory reclamation, this creates a 'check_flush_dependency' warning and a risk of deadlock under memory pressure during Queue Pair (QP) destruction. The fix involves adding the WQ_MEM_RECLAIM flag to the workqueue allocation in the hns_roce_v2_init_eq_table function.
Affected products
- Linux Linux Kernel hns_roce_hw_v2 driver
Timeline
- 2026-01-04: patched: Initial patch authored by Chengchang Tang
- 2026-06-03: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0cbec8b49270f3f0600b8e3ef5e8f0d233dcea27
- https://git.kernel.org/stable/c/12761bd0ae16a80f237c2a65ab1b1064076cc74a
- https://git.kernel.org/stable/c/562c96b1393da2df3ea62173c84117b39da353b9
- https://git.kernel.org/stable/c/70a5eb757ace5bd627a36f04d871eaf85def424d
- https://git.kernel.org/stable/c/c0a26bbd3f99b7b03f072e3409aff4e6ec8af6f6
- https://git.kernel.org/stable/c/c5ef9a1bcf5b597695d9c2e6ac452e9f89521862