Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/bnxt_re: Avoid repeated requests to allocate WC pages

Applications can request multiple WC pages for the same ucontext.
As of now, only 1 WC page per ucontext is supported. Add a lock to
avoid concurrent access and a check to fail repeated requests.
Also, if the mmap entry insert fails for the WC, free the Doorbell
page index mapped for the WC page.
Published: 2026-08-15
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The bnxt_re RDMA driver in the Linux kernel does not limit the number of write‑combining (WC) pages that can be requested for a single user context. When multiple requests are made concurrently, the driver lacks proper locking and performs no check to reject double requests. The fix adds a lock and a failure check, and ensures cleanup if a memory mapping fails. Because the driver previously allowed concurrent accesses, a sequence of repeated allocation requests could exhaust kernel resources or leave the driver in an inconsistent state, potentially resulting in a denial of service.

Affected Systems

Any system running the Linux kernel with the bnxt_re RDMA driver before the kernel update that includes the lock and check. The specific kernel versions are not listed, so any install using an unpatched kernel is considered vulnerable.

Risk and Exploitability

EPSS is below 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating limited publicly known exploitation. The flaw could be triggered by an RDMA client that repeatedly issues WC page allocation requests. Although the exact exploitation path is not documented, the absence of synchronization suggests that a repeated or concurrent request scenario could cause resource exhaustion or driver instability, hence the overall risk is considered moderate for environments that expose RDMA services. The CVSS score is 9.3, signaling a critical severity.

Generated by OpenCVE AI on August 22, 2026 at 03:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel release that includes the bnxt_re race condition fix.
  • If a kernel update cannot be applied immediately, avoid issuing multiple WC page allocation requests for the same user context.
  • Disable the bnxt_re RDMA driver or block RDMA network traffic if the feature is not required.

Generated by OpenCVE AI on August 22, 2026 at 03:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Sat, 15 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages Applications can request multiple WC pages for the same ucontext. As of now, only 1 WC page per ucontext is supported. Add a lock to avoid concurrent access and a check to fail repeated requests. Also, if the mmap entry insert fails for the WC, free the Doorbell page index mapped for the WC page.
Title RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:44:56.649Z

Reserved: 2026-08-09T03:40:39.937Z

Link: CVE-2026-72495

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:23.840

Modified: 2026-08-17T06:19:17.937

Link: CVE-2026-72495

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72495 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T04:00:12Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling