-

CVE-2026-90415

RDMA/cxgb4: free STAG index when TPT entry write fails

In the Linux kernel, the following vulnerability has been resolved:

RDMA/cxgb4: free STAG index when TPT entry write fails

write_tpt_entry() allocates a new STAG index with c4iw_get_resource() and
bumps stats.stag.cur before programming the entry.  When
write_adapter_mem() fails, it returns the error without releasing the index
or reversing the statistic.  No MR is inserted into rhp->mrs, so
deregistration never reclaims it, leaking the index until device teardown.

Record whether this call allocated the index and, on a failed write, return
it to tpt_table and decrement stats.stag.cur.  Key the rollback on both the
write error and that flag, not the error alone: a non-reset update carries
a caller-owned STAG that this call did not allocate and must not free.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ec3eead217181d7360a11317a888ceb30807867c
Version < 5fe4731bfbd8d83c4a14b4af3a27329969ce8a99
Status affected
Version ec3eead217181d7360a11317a888ceb30807867c
Version < 8f6976d635d190e3d7af7103daaa581cf1ccc12e
Status affected
Version ec3eead217181d7360a11317a888ceb30807867c
Version < 9eeafcda1d6c11f0eec532243c4e96ec8c632bd7
Status affected
Version ec3eead217181d7360a11317a888ceb30807867c
Version < 5a21e5114cec4cd3f8a2843d4c46bc49634d6e96
Status affected
Version ec3eead217181d7360a11317a888ceb30807867c
Version < 2f17ca7ab5269ac2504e1039c3921373dccd7712
Status affected
Version ec3eead217181d7360a11317a888ceb30807867c
Version < a2e37d1ab773be3cd26b1c19593ca2dbcece9c57
Status affected
Version ec3eead217181d7360a11317a888ceb30807867c
Version < a64e2beb450179a5d43034af8d5476a11eac1486
Status affected
Version ec3eead217181d7360a11317a888ceb30807867c
Version < fdfb5cea4bf070cdb31d997efd87bb684df041fd
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.5
Status affected
Version 0
Version < 3.5
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.075
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5fe4731bfbd8d83c4a14b4af3a27329969ce8a99
https://git.kernel.org/stable/c/8f6976d635d190e3d7af7103daaa581cf1ccc12e
https://git.kernel.org/stable/c/9eeafcda1d6c11f0eec532243c4e96ec8c632bd7
https://git.kernel.org/stable/c/5a21e5114cec4cd3f8a2843d4c46bc49634d6e96
https://git.kernel.org/stable/c/2f17ca7ab5269ac2504e1039c3921373dccd7712
https://git.kernel.org/stable/c/a2e37d1ab773be3cd26b1c19593ca2dbcece9c57
https://git.kernel.org/stable/c/a64e2beb450179a5d43034af8d5476a11eac1486
https://git.kernel.org/stable/c/fdfb5cea4bf070cdb31d997efd87bb684df041fd