CVE-2026-80625
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/hns: Fix memory leak of bonding resources
In a corner case of concurrent driver removal and driver reset, bonding resource is first released in hns_roce_hw_v2_exit() during driver removal, and then is allocated again in hns_roce_register_device() during driver reset. This leads to memory leak because the release timing has already passed. This may also lead to a kernel panic as below because of the leaked notifier callback:
Call trace: 0xffffa20fccc04978 (P) raw_notifier_call_chain+0x20/0x38 call_netdevice_notifiers_info+0x60/0xb8 netdev_lower_state_changed+0x4c/0xb8
As Sashiko suggested, the teardown order of bonding resources should be inverted to make sure the resources are released when the driver is removed.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | b37ad2e290fc52e575572b04803a4f93f584df6c < bc4caea7a82bbcf94a34eff7094e7f9b501680ab | affected |
| Linux | Linux | b37ad2e290fc52e575572b04803a4f93f584df6c < c0bd03b850d81a8914168d87ddf7f6ffa58875ef | affected |
| Linux | Linux | 6.19 | affected |
| Linux | Linux | 0 < 6.19 | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/bc4caea7a82bbcf94a34eff7094e7f9b501680ab
- https://git.kernel.org/stable/c/c0bd03b850d81a8914168d87ddf7f6ffa58875ef
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.