SB20260815172 - Improper resource shutdown or release in Linux kernel hw mlx5 driver
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-74296)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in the RDMA/mlx5 UAR deallocation logic when releasing a user access region index. A local user can trigger UAR allocation and release operations to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/449ae7927152e46acbe5f19f97eafdae6d3a96b1
- https://git.kernel.org/stable/c/6f83de384ca582fa87b4c2b0d03bd1ed3bf9a2ee
- https://git.kernel.org/stable/c/80f1f49f53a42733e60c90e0ec545e647969214d
- https://git.kernel.org/stable/c/aabfc845838ef453f1d22d7665596f9cc48be7dd
- https://git.kernel.org/stable/c/d3ff718c0c7153e2641e6a09507bace14fc5c402
- https://git.kernel.org/stable/c/ef369446f62903ea079e8a7954b5bf8bb8300fe3