Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/hfi1: Free RX data on late probe failure

hfi1_init_dd() allocates the shared AIP/VNIC RX support before returning.
If hfi1_init() or hfi1_register_ib_device() later fails, init_one() tears
down the device data without calling hfi1_free_rx(). This leaks netdev_rx
and its dummy netdev.

Free the RX support after IB unregistration and before postinit_cleanup(),
as done on normal device removal.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Resource Exhaustion
Action: Immediate Patch
AI Analysis

Impact

The RDMA/hfi1 driver in the Linux kernel does not release allocated RX support structures when initialization fails, causing a memory leak of netdev_rx and a dummy netdev. This unchecked resource consumption can lead to memory exhaustion, potentially causing a denial of service if the system runs out of available memory. The weakness corresponds to an improper release of resources (CWE-401).

Affected Systems

This flaw affects any Linux distribution that includes the RDMA/hfi1 driver in the kernel. Versions prior to the commit that adds a call to hfi1_free_rx() during error cleanup are vulnerable; affected kernel releases are unspecified in the advisory.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The attack vector is likely local, requiring privileged access to load or initialize the RDMA/hfi1 driver, so it is not remotely exploitable. Nonetheless, an adversary with system access could intentionally trigger repeated probe failures to exhaust memory and degrade availability.

Generated by OpenCVE AI on September 19, 2026 at 07:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that calls hfi1_free_rx() during failure cleanup or update to a kernel version that includes this fix
  • If update is not immediately possible, prevent the RDMA/hfi1 driver from loading by blacklisting it or removing the module until the patch is applied
  • Monitor system memory usage for signs of the leak and consider restarting the affected services or system if memory becomes constrained

Generated by OpenCVE AI on September 19, 2026 at 07:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Free RX data on late probe failure hfi1_init_dd() allocates the shared AIP/VNIC RX support before returning. If hfi1_init() or hfi1_register_ib_device() later fails, init_one() tears down the device data without calling hfi1_free_rx(). This leaks netdev_rx and its dummy netdev. Free the RX support after IB unregistration and before postinit_cleanup(), as done on normal device removal.
Title RDMA/hfi1: Free RX data on late probe failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:14.413Z

Reserved: 2026-09-17T16:02:15.085Z

Link: CVE-2026-93102

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:04.480

Modified: 2026-09-17T17:18:04.480

Link: CVE-2026-93102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:15:16Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime