Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/cxgb4: free STAG index when TPT entry write fails

write_tpt_entry() allocates a new STAG index with c4iw_get_resource() and
bumps stats.stag.cur before programming the entry. When
write_adapter_mem() fails, it returns the error without releasing the index
or reversing the statistic. No MR is inserted into rhp->mrs, so
deregistration never reclaims it, leaking the index until device teardown.

Record whether this call allocated the index and, on a failed write, return
it to tpt_table and decrement stats.stag.cur. Key the rollback on both the
write error and that flag, not the error alone: a non-reset update carries
a caller-owned STAG that this call did not allocate and must not free.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak that can lead to Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the RDMA/cxgb4 driver of the Linux kernel. When the write_tpt_entry function attempts to program a TPT entry and write_adapter_mem fails, the driver mistakenly fails to release the STAG index it previously allocated. The corresponding counter in stats.stag.cur is also left unchanged. Over time, this results in an unchecked growth of allocated indices, eventually exhausting kernel resources and degrading RDMA functionality.

Affected Systems

This issue affects all Linux kernel builds that include the cxgb4 RDMA driver. The specific affected kernel versions are not listed, so any deployment using the default Linux kernel with the cxgb4 driver should be considered potentially vulnerable until an updated kernel is available.

Risk and Exploitability

The EPSS score indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because it is a kernel bug, it requires privileged execution to exploit, though it could be triggered by normal kernel operation if the RDMA device experiences write failures. The potential impact is resource exhaustion that could lead to a denial of RDMA services or general kernel instability.

Generated by OpenCVE AI on September 19, 2026 at 06:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel release that incorporates the fix for the cxgb4 driver
  • If an immediate kernel upgrade is not feasible, unload or disable the cxgb4 module to prevent RDMA traffic from using the vulnerable driver
  • Monitor kernel logs for frequent write_adapter_mem failures and review STAG allocation statistics to detect early signs of leakage

Generated by OpenCVE AI on September 19, 2026 at 06:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: free STAG index when TPT entry write fails write_tpt_entry() allocates a new STAG index with c4iw_get_resource() and bumps stats.stag.cur before programming the entry. When write_adapter_mem() fails, it returns the error without releasing the index or reversing the statistic. No MR is inserted into rhp->mrs, so deregistration never reclaims it, leaking the index until device teardown. Record whether this call allocated the index and, on a failed write, return it to tpt_table and decrement stats.stag.cur. Key the rollback on both the write error and that flag, not the error alone: a non-reset update carries a caller-owned STAG that this call did not allocate and must not free.
Title RDMA/cxgb4: free STAG index when TPT entry write fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:40.714Z

Reserved: 2026-09-11T19:38:34.813Z

Link: CVE-2026-90415

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:45.647

Modified: 2026-09-17T17:17:45.647

Link: CVE-2026-90415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T11:30:06Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime