CVE-2026-23289
Received
Received - Intake
Memory Leak in Linux Kernel IB/mthca Component on Syscall Failure
Publication date: 2026-03-25
Last updated on: 2026-04-18
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq()
Fix a user triggerable leak on the system call failure path.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| linux_kernel | linux_kernel | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is in the Linux kernel related to the IB/mthca driver. It involves a missing call to mthca_unmap_user_db() in the function mthca_create_srq(). This omission causes a resource leak when a system call fails, which can be triggered by a user.
How can this vulnerability impact me? :
The vulnerability can lead to a resource leak in the system when certain system calls fail. This leak could potentially degrade system performance or stability over time if exploited repeatedly by a user.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70