Description
In the Linux kernel, the following vulnerability has been resolved:

vdpa/mlx5: fix wrong list iterated in add_direct_chain error path

In add_direct_chain(), newly allocated direct MR entries are added to
the local list 'tmp', which is spliced into mr->head only on success.
On the error path, the cleanup loop was incorrectly iterating over
mr->head instead of tmp.

Fix by iterating over 'tmp' in the err_alloc cleanup path.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Resource Leak
Action: Patch
AI Analysis

Impact

A defect in the Linux kernel’s vDPA/mlx5 driver causes the error path cleanup to iterate over the wrong list, leaving newly allocated direct memory registration entries untouched. This results in a kernel‑level resource leak, which could increase kernel memory usage.

Affected Systems

All Linux kernel versions that include the vDPA/mlx5 driver before the integration of commit 6ca752850 are affected. This includes mainstream distributions that ship the upstream kernel from any release series that contains the kernel prior to the fix. Exact version ranges depend on each distribution’s kernel packaging but can be identified by examining the patch level.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability. Based on the description, it is inferred that the attack vector is local or remote only if the attacker can gain privileged kernel code execution, because the flaw requires kernel‑level privileges or the ability to execute code in kernel context to cause the memory leak. Given the low likelihood and the nature of the defect, overall risk remains low.

Generated by OpenCVE AI on September 20, 2026 at 03:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that contains commit 6ca752850 or later, or rebuild the kernel with that commit applied.
  • Patch a custom kernel source by replacing the err_alloc loop to iterate over the correct temporary list.
  • Enable kernel memory usage monitoring and configure alerts for unusually high kernel memory consumption to detect potential leaks.

Generated by OpenCVE AI on September 20, 2026 at 03:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: fix wrong list iterated in add_direct_chain error path In add_direct_chain(), newly allocated direct MR entries are added to the local list 'tmp', which is spliced into mr->head only on success. On the error path, the cleanup loop was incorrectly iterating over mr->head instead of tmp. Fix by iterating over 'tmp' in the err_alloc cleanup path.
Title vdpa/mlx5: fix wrong list iterated in add_direct_chain error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:29.877Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90128

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:05.210

Modified: 2026-09-17T17:17:05.210

Link: CVE-2026-90128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:00:09Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime