Junglewise Threat Intelligence

CVE-2026-90415: Linux kernel RDMA/cxgb4 STAG index resource leak

CVE-2026-90415 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RDMA/cxgb4 driver contains a resource leak in memory registration handling. When writing a Translation and Protection Table (TPT) entry fails, the driver fails to release an allocated STAG index, causing kernel memory structures to accumulate over time until the device is shut down. This can lead to gradual resource exhaustion in systems heavily using Remote Direct Memory Access operations.

Technical details

The vulnerability is a resource leak in the write_tpt_entry() function within drivers/infiniband/hw/cxgb4/mem.c. The function allocates a STAG index using c4iw_get_resource() and increments stats.stag.cur before programming the TPT entry via write_adapter_mem(). When write_adapter_mem() fails, the function returns without releasing the allocated index or decrementing the statistics counter. Since no memory region (MR) is inserted into the resource tracking structure, the leaked index is never reclaimed during normal deregistration. The fix adds a flag to track whether this specific call allocated the STAG index, and only rolls back the allocation if the write operation fails and the index was locally allocated (not caller-owned).

Affected products

  • Linux Linux kernel all versions with RDMA/cxgb4 driver (before upstream fix commit fdfb5cea4bf070cdb31d997efd87bb684df041fd)

Timeline

  • 2026-09-17: disclosed: CVE published
  • 2026-07-26: patched: Upstream fix commit fdfb5cea4bf070cdb31d997efd87bb684df041fd

References

Related threats