SB20260325174 - Improper Resource Shutdown or Release in Linux kernel hw mthca driver
Published: March 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Resource Shutdown or Release (CVE-ID: CVE-2026-23289)
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper resource management in the IB/mthca subsystem when handling system calls. A local user can trigger a failed system call path to disclose sensitive information.
The issue arises from a missing mthca_unmap_user_db() call during error handling in mthca_create_srq(), leading to a resource leak that could expose system memory.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/117942ca43e2e3c3d121faae530989931b7f67e1
- https://git.kernel.org/stable/c/972b72d7e2d8fe1400f1c7a8304c282c539b7e02
- https://git.kernel.org/stable/c/d0148965dbca8cc8efa7e3d6e99940487bf661c0
- https://git.kernel.org/stable/c/da8eaa73bc37d004350ba68eb18b6ade8e49db52
- https://git.kernel.org/stable/c/deee46b37ebd8cc5ff810127883fca90f2412a7b
- https://git.kernel.org/stable/c/f67f1ad4029e9fa183141546de31987b254c9292