๐Ÿ” CVE Alert

CVE-2026-46176

HIGH 7.8

RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init()

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() mlx5_ib_dev_res_srq_init() allocates two SRQs, s0 and s1. When ib_create_srq() fails for s1, the error branch destroys s0 but falls through and unconditionally assigns the freed s0 and the ERR_PTR s1 to devr->s0 and devr->s1. This leads to several problems: the lock-free fast path checks "if (devr->s1) return 0;" and treats the ERR_PTR as already initialised; users in mlx5_ib_create_qp() dereference the freed SRQ or ERR_PTR via to_msrq(devr->s0)->msrq.srqn; and mlx5_ib_dev_res_cleanup() dereferences the ERR_PTR and double-frees s0 on teardown. Fix by adding the same `goto unlock` in the s1 failure path.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published May 28, 2026
Last Updated May 30, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
b6334d2356fc0922ed01457960f74923058a353a < a13c2ac4d480b734342c6fbf8249fc48afd675f3 5895e70f2e6e8dc67b551ca554d6fcde0a7f0467 < bc2cf5935b4665172235341163315905197ae91d 5895e70f2e6e8dc67b551ca554d6fcde0a7f0467 < b087913ae88256df66620f7ba0a9776716aeef7e 5895e70f2e6e8dc67b551ca554d6fcde0a7f0467 < 6fd93142dd1d09000c3750af08270f5792523fe9 5895e70f2e6e8dc67b551ca554d6fcde0a7f0467 < c488df06bd552bb8b6e14fa0cfd5ad986c6e9525 6.6.64 < 6.6.140
Linux / Linux
6.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a13c2ac4d480b734342c6fbf8249fc48afd675f3 git.kernel.org: https://git.kernel.org/stable/c/bc2cf5935b4665172235341163315905197ae91d git.kernel.org: https://git.kernel.org/stable/c/b087913ae88256df66620f7ba0a9776716aeef7e git.kernel.org: https://git.kernel.org/stable/c/6fd93142dd1d09000c3750af08270f5792523fe9 git.kernel.org: https://git.kernel.org/stable/c/c488df06bd552bb8b6e14fa0cfd5ad986c6e9525