{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80625","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.775Z","datePublished":"2026-08-28T06:48:43.583Z","dateUpdated":"2026-08-28T06:48:43.583Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-28T06:48:43.583Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix memory leak of bonding resources\n\nIn a corner case of concurrent driver removal and driver reset,\nbonding resource is first released in hns_roce_hw_v2_exit() during\ndriver removal, and then is allocated again in hns_roce_register_device()\nduring driver reset. This leads to memory leak because the release\ntiming has already passed. This may also lead to a kernel panic\nas below because of the leaked notifier callback:\n\nCall trace:\n  0xffffa20fccc04978 (P)\n  raw_notifier_call_chain+0x20/0x38\n  call_netdevice_notifiers_info+0x60/0xb8\n  netdev_lower_state_changed+0x4c/0xb8\n\nAs Sashiko suggested, the teardown order of bonding resources should\nbe inverted to make sure the resources are released when the driver\nis removed."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/hns/hns_roce_hw_v2.c"],"versions":[{"version":"b37ad2e290fc52e575572b04803a4f93f584df6c","lessThan":"bc4caea7a82bbcf94a34eff7094e7f9b501680ab","status":"affected","versionType":"git"},{"version":"b37ad2e290fc52e575572b04803a4f93f584df6c","lessThan":"c0bd03b850d81a8914168d87ddf7f6ffa58875ef","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/hns/hns_roce_hw_v2.c"],"versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/bc4caea7a82bbcf94a34eff7094e7f9b501680ab"},{"url":"https://git.kernel.org/stable/c/c0bd03b850d81a8914168d87ddf7f6ffa58875ef"}],"title":"RDMA/hns: Fix memory leak of bonding resources","x_generator":{"engine":"bippy-1.2.0"}}}}