Bug 2536631 (CVE-2026-90415) - CVE-2026-90415 kernel: RDMA/cxgb4: free STAG index when TPT entry write fails
Summary: CVE-2026-90415 kernel: RDMA/cxgb4: free STAG index when TPT entry write fails
Keywords:
Status: NEW
Alias: CVE-2026-90415
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-17 18:58 UTC by OSIDB Bzimport
Modified: 2026-10-05 13:47 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-17 18:58:20 UTC
In the Linux kernel, the following vulnerability has been resolved:

RDMA/cxgb4: free STAG index when TPT entry write fails

write_tpt_entry() allocates a new STAG index with c4iw_get_resource() and
bumps stats.stag.cur before programming the entry.  When
write_adapter_mem() fails, it returns the error without releasing the index
or reversing the statistic.  No MR is inserted into rhp->mrs, so
deregistration never reclaims it, leaking the index until device teardown.

Record whether this call allocated the index and, on a failed write, return
it to tpt_table and decrement stats.stag.cur.  Key the rollback on both the
write error and that flag, not the error alone: a non-reset update carries
a caller-owned STAG that this call did not allocate and must not free.


Note You need to log in before you can comment on or make changes to this bug.