Junglewise Threat Intelligence

CVE-2026-74299: Linux kernel RDMA/core memory leak in FRMR aging

CVE-2026-74299 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RDMA (Remote Direct Memory Access) subsystem contains a memory management issue in Fast Registered Memory Region (FRMR) pool aging. When the kernel attempts to move handles between memory queues during pool maintenance, it can fail to properly clean up resources under memory pressure, potentially leading to resource leaks. This affects systems using InfiniBand or RoCE (RDMA over Converged Ethernet) for high-performance networking.

Technical details

This is a resource-handling bug in the RDMA/core FRMR pool aging mechanism (drivers/infiniband/core/frmr_pools.c). The vulnerability occurs when moving pinned memory handles from an active queue to an inactive queue during pool aging; if page allocation fails under memory pressure (GFP_ATOMIC), the code did not properly handle the fault, leaking memory keys (mkeys). The fix introduces a new helper function splice_frmr_queue_locked() that performs queue splicing without requiring new page allocations, eliminating the failure path. The vulnerable code path is triggered during normal pool maintenance (pool_aging_work) on systems using FRMR for RDMA operations. No authentication or network access is required; exploitation is local to the kernel's internal memory management.

Affected products

  • Linux Linux kernel 5.0 and later (in FRMR-using versions)

Timeline

  • 2026-06-10: other: Patch authored by Michael Guralnik
  • 2026-06-11: patched: Patch merged into main kernel tree (commit c6936506ed556ce3ccad36ab999baf2764dd7d25)
  • 2026-08-15: disclosed: CVE-2026-74299 publicly disclosed
  • 2026-07-24: patched: Patch backported to stable kernel series

References

Related threats