« Volver al listado

CVE-2026-90415

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

RDMA/cxgb4: free STAG index when TPT entry write fails

write_tpt_entry() allocates a new STAG index with c4iw_get_resource() and bumps stats.stag.cur before programming the entry. When write_adapter_mem() fails, it returns the error without releasing the index or reversing the statistic. No MR is inserted into rhp->mrs, so deregistration never reclaims it, leaking the index until device teardown.

Record whether this call allocated the index and, on a failed write, return it to tpt_table and decrement stats.stag.cur. Key the rollback on both the write error and that flag, not the error alone: a non-reset update carries a caller-owned STAG that this call did not allocate and must not free.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90415",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ec3eead217181d7360a11317a888ceb30807867c",
              "lessThan": "5fe4731bfbd8d83c4a14b4af3a27329969ce8a99",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ec3eead217181d7360a11317a888ceb30807867c",
              "lessThan": "8f6976d635d190e3d7af7103daaa581cf1ccc12e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ec3eead217181d7360a11317a888ceb30807867c",
              "lessThan": "9eeafcda1d6c11f0eec532243c4e96ec8c632bd7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ec3eead217181d7360a11317a888ceb30807867c",
              "lessThan": "5a21e5114cec4cd3f8a2843d4c46bc49634d6e96",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ec3eead217181d7360a11317a888ceb30807867c",
              "lessThan": "2f17ca7ab5269ac2504e1039c3921373dccd7712",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ec3eead217181d7360a11317a888ceb30807867c",
              "lessThan": "a2e37d1ab773be3cd26b1c19593ca2dbcece9c57",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ec3eead217181d7360a11317a888ceb30807867c",
              "lessThan": "a64e2beb450179a5d43034af8d5476a11eac1486",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ec3eead217181d7360a11317a888ceb30807867c",
              "lessThan": "fdfb5cea4bf070cdb31d997efd87bb684df041fd",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/infiniband/hw/cxgb4/mem.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/infiniband/hw/cxgb4/mem.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:45.647",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2f17ca7ab5269ac2504e1039c3921373dccd7712",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5a21e5114cec4cd3f8a2843d4c46bc49634d6e96",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5fe4731bfbd8d83c4a14b4af3a27329969ce8a99",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8f6976d635d190e3d7af7103daaa581cf1ccc12e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9eeafcda1d6c11f0eec532243c4e96ec8c632bd7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a2e37d1ab773be3cd26b1c19593ca2dbcece9c57",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a64e2beb450179a5d43034af8d5476a11eac1486",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fdfb5cea4bf070cdb31d997efd87bb684df041fd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/cxgb4: free STAG index when TPT entry write fails\n\nwrite_tpt_entry() allocates a new STAG index with c4iw_get_resource() and\nbumps stats.stag.cur before programming the entry.  When\nwrite_adapter_mem() fails, it returns the error without releasing the index\nor reversing the statistic.  No MR is inserted into rhp->mrs, so\nderegistration never reclaims it, leaking the index until device teardown.\n\nRecord whether this call allocated the index and, on a failed write, return\nit to tpt_table and decrement stats.stag.cur.  Key the rollback on both the\nwrite error and that flag, not the error alone: a non-reset update carries\na caller-owned STAG that this call did not allocate and must not free."
    }
  ],
  "lastModified": "2026-09-17T17:17:45.647",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}