Executive brief
The Linux kernel's Thunderbolt networking driver contains a resource leak in the receive (Rx) HopID allocation path. When the kernel allocates a network resource ID but receives a different one than expected, it fails to properly release the incorrectly allocated ID, leaving system resources unavailable for the duration of the connection. This can eventually exhaust the pool of available resources, degrading system performance or preventing new Thunderbolt connections.
Technical details
The vulnerability is a resource leak (CWE-404) in the Linux kernel's Thunderbolt networking driver (drivers/net/thunderbolt/main.c). The function tbnet_connected_work() calls tb_xdomain_alloc_in_hopid() to allocate a receive HopID, but the ID allocator may return a different ID than requested (the next available one above the requested value). When this mismatch occurs, the function returns an error without releasing the incorrectly allocated ID via tb_xdomain_release_in_hopid(). This leaves the allocated resource unreleased for the entire XDomain connection lifetime. The fix adds a conditional release of the mismatched HopID when ret >= 0 but ret != net->remote_transmit_path. No network access or authentication is required; the issue manifests during normal Thunderbolt XDomain connection setup.
Affected products
- Linux Linux kernel Affected since kernel 4.20 (introduction of DMA tunnels feature); fix available in mainline and stable branches
Timeline
- 2026-09-11: disclosed: Published in NVD
- 2026-08-17: patched: Fix merged to mainline kernel
- 2026-09-07: patched: Fix backported to stable kernel branches