In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure mlx5r_umr_update_xlt()… (CVE-2026-74396)
A vulnerability in the Linux kernel's RDMA mlx5 driver was resolved involving improper cleanup of XLT buffers and DMA mappings on ODP populate failure. The issue caused resource leaks and a mutex to remain locked under certain error conditions. The fix ensures proper cleanup by adjusting control flow to reach the existing cleanup path.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel's RDMA/mlx5 component involved the mlx5r_umr_update_xlt() function, which allocates and DMA maps an XLT buffer. After the mlx5_odp_populate_xlt() function became fallible, its error path returned early, skipping the common cleanup routine mlx5r_umr_unmap_free_xlt(). This led to leaks of the XLT DMA mapping and buffer, and if the emergency XLT page was used, the xlt_emergency_page_mutex remained locked. The patch corrected this by breaking out of the loop to allow execution to fall through to the existing cleanup path, preventing resource leaks and mutex deadlock.
Potential Impact
The vulnerability causes resource leaks of DMA mappings and buffers, and can leave a mutex locked, potentially impacting system stability or causing deadlocks in the RDMA mlx5 driver. There is no indication of direct security compromise such as privilege escalation or code execution from the provided data.
Mitigation Recommendations
A fix for this vulnerability has been applied in the Linux kernel. Users should update to the fixed kernel version containing this patch. Since this is a kernel-level fix, applying the official kernel update from the vendor or distribution is the recommended remediation. Patch status is not explicitly stated but the vulnerability is described as resolved.
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure mlx5r_umr_update_xlt()… (CVE-2026-74396)
Description
A vulnerability in the Linux kernel's RDMA mlx5 driver was resolved involving improper cleanup of XLT buffers and DMA mappings on ODP populate failure. The issue caused resource leaks and a mutex to remain locked under certain error conditions. The fix ensures proper cleanup by adjusting control flow to reach the existing cleanup path.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel's RDMA/mlx5 component involved the mlx5r_umr_update_xlt() function, which allocates and DMA maps an XLT buffer. After the mlx5_odp_populate_xlt() function became fallible, its error path returned early, skipping the common cleanup routine mlx5r_umr_unmap_free_xlt(). This led to leaks of the XLT DMA mapping and buffer, and if the emergency XLT page was used, the xlt_emergency_page_mutex remained locked. The patch corrected this by breaking out of the loop to allow execution to fall through to the existing cleanup path, preventing resource leaks and mutex deadlock.
Potential Impact
The vulnerability causes resource leaks of DMA mappings and buffers, and can leave a mutex locked, potentially impacting system stability or causing deadlocks in the RDMA mlx5 driver. There is no indication of direct security compromise such as privilege escalation or code execution from the provided data.
Mitigation Recommendations
A fix for this vulnerability has been applied in the Linux kernel. Users should update to the fixed kernel version containing this patch. Since this is a kernel-level fix, applying the official kernel update from the vendor or distribution is the recommended remediation. Patch status is not explicitly stated but the vulnerability is described as resolved.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-2vqx-xvhw-m854
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-74396"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a808b69bf8831d5394f5d1a
Added to database: 08/15/2026, 15:53:13 UTC
Last enriched: 08/15/2026, 16:02:50 UTC
Last updated: 08/15/2026, 16:02:50 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.