Junglewise Threat Intelligence

CVE-2026-80625: Linux kernel RDMA/hns memory leak in bonding resource teardown

CVE-2026-80625 · Severity: info · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RDMA/hns driver has a memory leak in how it manages bonding resources during driver removal and reset. In rare cases where driver removal and reset occur concurrently, resources are released at the wrong time, causing them to be reallocated and never properly freed. This can also trigger kernel panic due to dangling notifier callbacks, disrupting system stability.

Technical details

The vulnerability is a resource management bug (CWE-401: missing release of memory after effective lifetime) in the RDMA/hns driver's exit handler. The root cause is incorrect teardown ordering: bonding resources are deallocated via hns_roce_dealloc_bond_grp() before unregistering the client via hnae3_unregister_client(), allowing a concurrent driver reset to reallocate those resources before deallocation completes. This creates a leaked notifier callback that can panic the kernel when network state changes occur. The fix inverts the teardown order, ensuring the client is unregistered first (preventing reset operations) before bonding resource deallocation. The vulnerability requires concurrent driver removal and reset—a race condition—and affects the Linux kernel RDMA subsystem. Patches are available in upstream commits c0bd03b850d81a8914168d87ddf7f6ffa58875ef and bc4caea7a82bbcf94a34eff7094e7f9b501680ab.

Affected products

  • Linux Linux kernel multiple versions (see stable branches linux-5.4.y through linux-6.9.y and later)

Timeline

  • 2026-08-28: disclosed: Published on NVD
  • 2026-06-13: patched: Original fix commit by Junxian Huang
  • 2026-06-16: patched: Merged upstream commit c0bd03b850d81a8914168d87ddf7f6ffa58875ef
  • 2026-07-24: patched: Backported to stable trees (bc4caea7a82bbcf94a34eff7094e7f9b501680ab)

References

Related threats