Improper control of a resource through its lifetime in Linux kernel - CVE-2026-46084
Published: May 27, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown in RSS queue pair destruction in mana_ib when destroying an RSS queue pair while traffic continues to arrive and the VF interface is subsequently brought up. A local user can destroy an RSS queue pair and trigger interface reinitialization while traffic is still being received to cause a denial of service.
The issue involves stale vPort RX steering configuration in firmware that can direct RX completions to reused TX completion queues.
How to mitigate CVE-2026-46084
Sources
- https://git.kernel.org/stable/c/3be5ed233de03b00ae868cfc06e95331d8d9007c
- https://git.kernel.org/stable/c/6a2d6273b6c3581ce7b90ce17b5cbb4efd19438f
- https://git.kernel.org/stable/c/8ba804869382ce307f2a15f5f6f2adfd791f41dc
- https://git.kernel.org/stable/c/dbeb256e8dd87233d891b170c0b32a6466467036
- https://git.kernel.org/stable/c/f1ccc4d500a0b87a5599343fc2f798048836e184