Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_entry()

When the device is in the fatal error state, write_tpt_entry() returns -EIO
before handing the caller's preallocated skb to the transmit path; its
allocation-failure returns do the same. c4iw_dereg_mr() ignores the error
and frees mhp, leaking mhp->dereg_skb. c4iw_get_dma_mr() instead frees the
skb a second time after dereg_mem() already consumed it, a double free.

Make write_tpt_entry() the sole owner of a non-NULL skb, freeing it on
every return preceding handoff to c4iw_ofld_send(): fatal error, tpt and
stag allocation failure. c4iw_ofld_send() consumes the skb on success and
error alike, so drop the redundant kfree_skb() in c4iw_get_dma_mr() after
dereg_mem().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

The vulnerability arises from improper handling of a socket buffer in the Linux‑kernel RDMA cxgb4 driver during error conditions. When the device enters a fatal error state, the write_tpt_entry() function returns an error before handing off the preallocated skb to the transmit path, causing a memory leak. Additionally, a double free occurs when c4iw_get_dma_mr() frees the same skb after dereg_mem() has already consumed it. Both a memory leak and a double free can corrupt kernel memory or exhaust resources, resulting in system instability, crashes, or a denial of service.

Affected Systems

Linux kernel, cxgb4 RDMA driver. No specific version information is supplied; any kernel build that includes the affected code path is potentially impacted.

Risk and Exploitability

The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The CVSS score is not provided, so the severity cannot be determined from the available data. Exploitation would likely require local access to interact with the RDMA subsystem, making it a local denial-of-service risk. No active exploit is known.

Generated by OpenCVE AI on September 19, 2026 at 14:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official kernel patch that resolves the double free and memory‑leak issue in the cxgb4 driver.
  • If immediate patching is not feasible, unload or disable the cxgb4 kernel module (e.g., with rmmod or modprobe -r cxgb4) to prevent the driver from handling RDMA traffic.
  • For environments that do not require RDMA, consider removing the network adapter that uses cxgb4 or disabling the RDMA subsystem via sysctl configuration.

Generated by OpenCVE AI on September 19, 2026 at 14:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_entry() When the device is in the fatal error state, write_tpt_entry() returns -EIO before handing the caller's preallocated skb to the transmit path; its allocation-failure returns do the same. c4iw_dereg_mr() ignores the error and frees mhp, leaking mhp->dereg_skb. c4iw_get_dma_mr() instead frees the skb a second time after dereg_mem() already consumed it, a double free. Make write_tpt_entry() the sole owner of a non-NULL skb, freeing it on every return preceding handoff to c4iw_ofld_send(): fatal error, tpt and stag allocation failure. c4iw_ofld_send() consumes the skb on success and error alike, so drop the redundant kfree_skb() in c4iw_get_dma_mr() after dereg_mem().
Title RDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_entry()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:42.342Z

Reserved: 2026-09-11T19:38:34.813Z

Link: CVE-2026-90417

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:46.050

Modified: 2026-09-17T17:17:46.050

Link: CVE-2026-90417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:30:07Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-416

    Use After Free