Junglewise Threat Intelligence

CVE-2026-74298: Linux kernel RDMA/core FRMR resource leak in error path

CVE-2026-74298 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RDMA (Remote Direct Memory Access) core module contains a resource leak in its FRMR (Fast Registration Memory Region) pool handling. When the kernel fails to add pinned memory region handles to a pool, it does not properly clean up the allocated resources, leading to a memory leak that could gradually exhaust system resources.

Technical details

This is a resource management bug in the RDMA/core FRMR pools subsystem. The vulnerability exists in the error path of the ib_frmr_pools_set_pinned() function in drivers/infiniband/core/frmr_pools.c. When push_handle_to_queue_locked() fails during the insertion of FRMR handles into the pool queue, the code previously skipped cleanup, leaving allocated FRMR handles undestroyed. The fix adds proper destruction of the remaining handles when a push operation fails, preventing resource exhaustion. This affects any system using RDMA with Fast Registration Memory Regions enabled, particularly in scenarios where pool allocation failures occur.

Affected products

  • Linux Linux kernel all versions with FRMR pool support

Timeline

  • 2026-08-15: disclosed
  • 2026-06-11: patched: Upstream fix committed

References

Related threats