Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-43260
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in the bnxt_en RSS context delete logic when deleting RSS contexts during interface close and subsequent restoration. A local user can trigger repeated RSS context deletion and restoration cycles to cause a denial of service.
The issue can cause firmware VNIC resources to be leaked, and subsequent open operations may fail to restore active RSS contexts.