Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/cxgb4: Free debugfs on registration failure

c4iw_alloc() creates the per-device debugfs tree (dev->debugfs_root via
setup_debugfs()), but it is removed only in c4iw_remove(), not in
c4iw_dealloc(). When RDMA device registration fails, the registration
worker's err_dealloc_ctx path calls c4iw_dealloc() directly, bypassing
c4iw_remove(), so the debugfs dentries leak and outlive the freed
c4iw_dev.

Move debugfs_remove_recursive() into c4iw_dealloc() so every path that
frees ctx->dev also removes its debugfs tree.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion via DebugFS Leak
Action: Patch kernel
AI Analysis

Impact

The kernel routine responsible for allocating debugging filesystem entries for RDMA devices fails to clean up those entries if the device registration itself fails. As a result, debugfs dentries accumulate and persist even after the underlying device structure is freed. Over time this leak can consume kernel memory and debugfs space, potentially triggering out-of-memory conditions or forcing the kernel to purge the debugfs hierarchy, which can lead to instability or a denial of service for applications relying on RDMA communication.

Affected Systems

All Linux kernel implementations that include the cxgb4 (c4iw) driver before the patch are affected. The vulnerability is present in any distribution using a kernel version that was released prior to the commit that moved debugfs_remove_recursive() into the deallocation path. The vendor is the Linux Foundation, and the CPE for the affected product is cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*.

Risk and Exploitability

The EPSS score is reported as < 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further suggesting it has not been observed in large‑scale attacks. Exploitation would likely require repeated failures of RDMA device registration, which is usually a local, privileged operation. Because the attack does not provide remote code execution, the risk is mainly a local or compromised system denial of service through resource exhaustion.

Generated by OpenCVE AI on September 19, 2026 at 03:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the commit adding debugfs_remove_recursive() to c4iw_dealloc()
  • If an immediate kernel upgrade is not possible, unload or blacklist the cxgb4 (c4iw) driver to stop further debugfs leaks
  • Investigate and address hardware or configuration issues that cause RDMA device registration failures to reduce the frequency of leaks

Generated by OpenCVE AI on September 19, 2026 at 03:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399
CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Free debugfs on registration failure c4iw_alloc() creates the per-device debugfs tree (dev->debugfs_root via setup_debugfs()), but it is removed only in c4iw_remove(), not in c4iw_dealloc(). When RDMA device registration fails, the registration worker's err_dealloc_ctx path calls c4iw_dealloc() directly, bypassing c4iw_remove(), so the debugfs dentries leak and outlive the freed c4iw_dev. Move debugfs_remove_recursive() into c4iw_dealloc() so every path that frees ctx->dev also removes its debugfs tree.
Title RDMA/cxgb4: Free debugfs on registration failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:30.778Z

Reserved: 2026-09-11T19:38:34.793Z

Link: CVE-2026-90219

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:17.290

Modified: 2026-09-17T17:17:17.290

Link: CVE-2026-90219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T04:00:07Z

Weaknesses