CVE-2026-93037

Summary

In the Linux kernel, the following vulnerability has been resolved:

RDMA/hfi1: Propagate sdma_txinit_ahg() errors

set_txreq_header_ahg() ignores the return value of sdma_txinit_ahg().

If sdma_txinit_ahg() fails, it returns before initializing tx->txreq. However, set_txreq_header_ahg() ignores the error and returns the AHG change count, causing the caller to continue processing the request as though initialization had succeeded.

Propagate sdma_txinit_ahg() failures to the caller and abort request processing when initialization fails.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxe3304b7cc4f14d365f46d6847a35563ae8b017f7 < cb73c2fe6e9cf563c99f22b7c8bca0d5f70d603eaffected
LinuxLinuxe3304b7cc4f14d365f46d6847a35563ae8b017f7 < 122a730675565ff2ad210537c3fc3afb8291d482affected
LinuxLinuxe3304b7cc4f14d365f46d6847a35563ae8b017f7 < bf974994150cfd14bfc599748925f4d426e00d90affected
LinuxLinuxe3304b7cc4f14d365f46d6847a35563ae8b017f7 < fd6dee13f3857259b6b2ddd28e1ed95fd94ae2f9affected
LinuxLinuxe3304b7cc4f14d365f46d6847a35563ae8b017f7 < 5b7cefffd15d87c8103865f887cdcf9077d8094baffected
LinuxLinuxe3304b7cc4f14d365f46d6847a35563ae8b017f7 < 3416db552eb378e54cb2f2ce0db5f0df88654bdaaffected
LinuxLinuxe3304b7cc4f14d365f46d6847a35563ae8b017f7 < ca99431820e8cac19f6a091c04da54cbe8d64f52affected
LinuxLinuxe3304b7cc4f14d365f46d6847a35563ae8b017f7 < 091c6162c022cbdfb64219708a71728cfd1d4600affected
LinuxLinux4.14affected
LinuxLinux0 < 4.14unaffected
LinuxLinux5.10.270 <= 5.10.*unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References