Home

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() Sashiko points out there are two bugs here in the error unwind flow, both related to how the WQ table is unwound. First there is a double i-- on the first failure path due to the while loop having a i--, remove it. Second if mana_ib_install_cq_cb() fails then mana_create_wq_obj() is not undone due to the above i--.

PUBLISHED Reserved 2026-05-13 | Published 2026-05-28 | Updated 2026-05-28 | Assigner Linux

Product status

Default status
unaffected

c15d7802a42402a87880a17eee89ff023e49ecc0 (git) before 8f23eb6c50f1a4bf32fc4d62cfb9fc39e8e586cf
affected

c15d7802a42402a87880a17eee89ff023e49ecc0 (git) before bb9cb36eaefa4dcb7c0d9f7a01e5c739abdd53a8
affected

c15d7802a42402a87880a17eee89ff023e49ecc0 (git) before 9a05a6798177e44dfbe18393be2c1ebb89ab06fd
affected

c15d7802a42402a87880a17eee89ff023e49ecc0 (git) before 34ecf795692ee57c393109f4a24ccc313091e137
affected

Default status
affected

6.8
affected

Any version before 6.8
unaffected

6.12.88 (semver)
unaffected

6.18.30 (semver)
unaffected

7.0.7 (semver)
unaffected

7.1-rc3 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/8f23eb6c50f1a4bf32fc4d62cfb9fc39e8e586cf

git.kernel.org/...c/bb9cb36eaefa4dcb7c0d9f7a01e5c739abdd53a8

git.kernel.org/...c/9a05a6798177e44dfbe18393be2c1ebb89ab06fd

git.kernel.org/...c/34ecf795692ee57c393109f4a24ccc313091e137

cve.org (CVE-2026-46126)

nvd.nist.gov (CVE-2026-46126)

Download JSON