CVE-2026-46126
Beschrijving NL
In de Linux kernel is de volgende kwetsbaarheid verholpen:
RDMA/mana: Fix mana_destroy_wq_obj() opruimen in mana_ib_create_qp_rss()
Sashiko wijst erop dat er hier twee bugs zijn in de foutafwikkelingsstroom, beide
gerelateerd aan hoe de WQ-tabel wordt afgewikkeld.
Eerst is er een dubbele i-- op het eerste storingspad vanwege de while-lus
met een i--, verwijder het.
Ten tweede, als mana_ib_install_cq_cb() mislukt, is mana_create_wq_obj() niet
ongedaan gemaakt vanwege de bovenstaande i--.
Origineel (Engels) tonen
In the Linux kernel, the following vulnerability has been resolved:
RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss()
Sashiko points out there are two bugs here in the error unwind flow, both
related to how the WQ table is unwound.
First there is a double i-- on the first failure path due to the while loop
having a i--, remove it.
Second if mana_ib_install_cq_cb() fails then mana_create_wq_obj() is not
undone due to the above i--.