Executive brief
The Linux kernel's RDMA mlx5 driver contains a memory leak in the UMR (User Memory Region) handling code. When ODP (On-Demand Paging) XLT population fails, the driver skips cleanup of allocated DMA buffers and may leave a mutex locked. This can cause resource exhaustion over time and potential denial of service if the emergency path is triggered repeatedly.
Technical details
The vulnerability is a resource leak in the RDMA/mlx5 driver's mlx5r_umr_update_xlt() function. When mlx5_odp_populate_xlt() returns an error, the code path immediately returns without executing the cleanup path (mlx5r_umr_unmap_free_xlt()) that frees DMA-mapped XLT buffers. Additionally, if the emergency XLT page was allocated, the xlt_emergency_page_mutex remains locked. The fix changes a direct return to a break statement, allowing execution to fall through to proper cleanup. The vulnerable code affects all kernel versions with the fallible mlx5_odp_populate_xlt() call introduced by commit 1efe8c0670d6.
Affected products
- Linux Linux kernel All versions with RDMA mlx5 ODP support (approximately 5.13+)
Timeline
- 2026-08-15: disclosed
- 2026-05-18: patched: Upstream fix committed; backport to stable series by 2026-07-24