Executive brief
The mlx5 InfiniBand driver in the Linux kernel fails to properly clean up allocated transport domain resources when loopback initialization encounters an error. This resource leak could lead to kernel memory exhaustion and system instability if triggered repeatedly, affecting systems using mlx5-based InfiniBand network adapters.
Technical details
The vulnerability is a resource leak in mlx5_ib_alloc_transport_domain() in drivers/infiniband/hw/mlx5/main.c. When mlx5_ib_enable_lb() returns an error after a transport domain has been successfully allocated, the allocated TD is not deallocated, causing a memory leak. The fix adds proper error handling to deallocate the TD via mlx5_cmd_dealloc_transport_domain() on mlx5_ib_enable_lb() failure, and moves the lb.mutex initialization from mlx5_ib_stage_caps_init() to mlx5_ib_stage_init_init() to ensure consistent initialization. No authentication or special privileges are required; the leak can be triggered through normal device initialization paths.
Affected products
- Linux Linux kernel Multiple versions; affected by commit 146d2f1af324 and fixed upstream
Timeline
- 2026-08-15: disclosed
- 2026-07-24: patched: Fix committed to stable trees