RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
Summary
| CVE | CVE-2026-74395 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 06:22:41 UTC |
| Updated | 2026-08-15 06:22:41 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
MLX5_IB_METHOD_DEVX_SUBSCRIBE_EVENT() links event_sub into sub_list
before initializing the fields used by the shared error path.
If eventfd_ctx_fdget() then fails, the unwind path dereferences
event_sub->ev_file in uverbs_uobject_put() and calls
subscribe_event_xa_dealloc() with an unset xa_key_level1.
subscribe_event_xa_alloc() creates the XA entry exactly once for a given
key_level1, on the first occurrence of that key. The unwind path must
therefore call subscribe_event_xa_dealloc() exactly once for it as well.
Enforce that by adding devx_key_in_sub_list() and calling
subscribe_event_xa_dealloc() only when the last matching pending entry is
being cleaned up. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 7597385371425febdaa8c6a1da3625d4ffff16f5 6e15b770461eeaa0ff73934922cb670a6a9db04e git |
Not specified |
| CNA |
Linux |
Linux |
affected 7597385371425febdaa8c6a1da3625d4ffff16f5 9be9aca28424228586fe9211c373ebdb826ebb6c git |
Not specified |
| CNA |
Linux |
Linux |
affected 7597385371425febdaa8c6a1da3625d4ffff16f5 f345e744b6b087188cde2377da5cbe9713b61353 git |
Not specified |
| CNA |
Linux |
Linux |
affected 7597385371425febdaa8c6a1da3625d4ffff16f5 1025dc2f7ba29b04b8687790fa91f9cd1a53141e git |
Not specified |
| CNA |
Linux |
Linux |
affected 7597385371425febdaa8c6a1da3625d4ffff16f5 7921821fc2b19c01588311f6e7468ae5b68b1f61 git |
Not specified |
| CNA |
Linux |
Linux |
affected 7597385371425febdaa8c6a1da3625d4ffff16f5 5100febf8e9d6c8c5ba8dc6534c6a5e3376e5989 git |
Not specified |
| CNA |
Linux |
Linux |
affected 7597385371425febdaa8c6a1da3625d4ffff16f5 78b9589fda266c71f0f9d0c858d4fa7381a890a5 git |
Not specified |
| CNA |
Linux |
Linux |
affected 7597385371425febdaa8c6a1da3625d4ffff16f5 43f8f7946814c8e5f464518246fdbc69b6e32326 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.3 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.3 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.261 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.212 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.178 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.145 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.97 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.40 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.5 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/43f8f7946814c8e5f464518246fdbc69b6e32326 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6e15b770461eeaa0ff73934922cb670a6a9db04e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/1025dc2f7ba29b04b8687790fa91f9cd1a53141e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/9be9aca28424228586fe9211c373ebdb826ebb6c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f345e744b6b087188cde2377da5cbe9713b61353 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7921821fc2b19c01588311f6e7468ae5b68b1f61 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5100febf8e9d6c8c5ba8dc6534c6a5e3376e5989 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/78b9589fda266c71f0f9d0c858d4fa7381a890a5 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.