Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-74396— RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure

CVSS 7.5 · High EPSS 0.52% · P42

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 8

VendorProductVersion RangeStatus
LinuxLinux1efe8c0670d6a6883faa09c9abc746c741f5664a< ffa85a2c197935ace6f1634ad9eb0a44bc615670affected
1efe8c0670d6a6883faa09c9abc746c741f5664a< 9619909d4869afe720904c6888a289b9ac3055b8affected
1efe8c0670d6a6883faa09c9abc746c741f5664a< 1eae35b37923cb71b0cb5136d00671440d488b9faffected
6.16affected
< 6.16unaffected
6.18.40≤ 6.18.*unaffected
7.1.5≤ 7.1.*unaffected
7.2≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-74396

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure mlx5r_umr_update_xlt() allocates and DMA maps an XLT buffer with mlx5r_umr_create_xlt(). The buffer is released by the common cleanup path through mlx5r_umr_unmap_free_xlt(). After mlx5_odp_populate_xlt() became fallible, its error path returned directly and skipped that cleanup. This leaks the XLT DMA mapping and buffer. If the emergency XLT page was used, it also leaves xlt_emergency_page_mutex locked. Break out of the loop so execution falls through the existing cleanup path.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 6.16版本存在安全漏洞,该漏洞源于mlx5_odp_populate_xlt()失败时错误路径直接返回,跳过XLT缓冲区清理,导致DMA映射和缓冲区泄漏,并可能使紧急XLT页互斥锁保持锁定,可能导致拒绝服务攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 1efe8c0670d6a6883faa09c9abc746c741f5664a ~ ffa85a2c197935ace6f1634ad9eb0a44bc615670 -
LinuxLinux 6.16 -

II. Public POCs for CVE-2026-74396

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-74396

登录查看更多情报信息。

Patches & Fixes for CVE-2026-74396 (3)

Same Patch Batch · Linux · 2026-08-15 · 845 CVEs total

CVE-2026-7430910.0 CRITICALvdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
CVE-2026-7428010.0 CRITICALcrypto: marvell/octeontx - fix DMA cleanup using wrong loop index
CVE-2026-7427910.0 CRITICALcrypto: cavium/cpt - fix DMA cleanup using wrong loop index
CVE-2026-7240710.0 CRITICALgeneve: validate inner network offset in geneve_gro_complete()
CVE-2026-7240810.0 CRITICALgeneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVE-2026-7447510.0 CRITICALvxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-7242110.0 CRITICALipv4: fib: Don't ignore error route in local/main tables.
CVE-2026-724939.9 CRITICALnet: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-743769.8 CRITICALmd/raid10: reset read_slot when reusing r10bio for discard
CVE-2026-722349.8 CRITICALbatman-adv: access unicast_ttvn skb->data only after skb realloc
CVE-2026-723399.8 CRITICALqede: fix off-by-one in BD ring consumption on build_skb failure
CVE-2026-742559.8 CRITICALtipc: fix UAF in tipc_l2_send_msg()
CVE-2026-720649.8 CRITICALnet: mana: Sync page pool RX frags for CPU
CVE-2026-720659.8 CRITICALnet: mana: Validate the packet length reported by the NIC
CVE-2026-722179.8 CRITICALSUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
CVE-2026-744739.8 CRITICALvxlan: use pskb_network_may_pull() in route_shortcircuit()
CVE-2026-723239.8 CRITICALipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
CVE-2026-744959.8 CRITICALigbvf: Fix leak in TX DMA error cleanup
CVE-2026-724639.8 CRITICALxfrm: Fix dev use-after-free in xfrm async resumption
CVE-2026-720699.8 CRITICALlocking/rt: Fix the incorrect RCU protection in rt_spin_unlock()

Showing top 20 of 845 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-74396

No comments yet


Leave a comment