{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90415","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.813Z","datePublished":"2026-09-17T16:09:40.714Z","dateUpdated":"2026-09-17T16:09:40.714Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-17T16:09:40.714Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/cxgb4: free STAG index when TPT entry write fails\n\nwrite_tpt_entry() allocates a new STAG index with c4iw_get_resource() and\nbumps stats.stag.cur before programming the entry.  When\nwrite_adapter_mem() fails, it returns the error without releasing the index\nor reversing the statistic.  No MR is inserted into rhp->mrs, so\nderegistration never reclaims it, leaking the index until device teardown.\n\nRecord whether this call allocated the index and, on a failed write, return\nit to tpt_table and decrement stats.stag.cur.  Key the rollback on both the\nwrite error and that flag, not the error alone: a non-reset update carries\na caller-owned STAG that this call did not allocate and must not free."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/cxgb4/mem.c"],"versions":[{"version":"ec3eead217181d7360a11317a888ceb30807867c","lessThan":"5fe4731bfbd8d83c4a14b4af3a27329969ce8a99","status":"affected","versionType":"git"},{"version":"ec3eead217181d7360a11317a888ceb30807867c","lessThan":"8f6976d635d190e3d7af7103daaa581cf1ccc12e","status":"affected","versionType":"git"},{"version":"ec3eead217181d7360a11317a888ceb30807867c","lessThan":"9eeafcda1d6c11f0eec532243c4e96ec8c632bd7","status":"affected","versionType":"git"},{"version":"ec3eead217181d7360a11317a888ceb30807867c","lessThan":"5a21e5114cec4cd3f8a2843d4c46bc49634d6e96","status":"affected","versionType":"git"},{"version":"ec3eead217181d7360a11317a888ceb30807867c","lessThan":"2f17ca7ab5269ac2504e1039c3921373dccd7712","status":"affected","versionType":"git"},{"version":"ec3eead217181d7360a11317a888ceb30807867c","lessThan":"a2e37d1ab773be3cd26b1c19593ca2dbcece9c57","status":"affected","versionType":"git"},{"version":"ec3eead217181d7360a11317a888ceb30807867c","lessThan":"a64e2beb450179a5d43034af8d5476a11eac1486","status":"affected","versionType":"git"},{"version":"ec3eead217181d7360a11317a888ceb30807867c","lessThan":"fdfb5cea4bf070cdb31d997efd87bb684df041fd","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/cxgb4/mem.c"],"versions":[{"version":"3.5","status":"affected"},{"version":"0","lessThan":"3.5","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5fe4731bfbd8d83c4a14b4af3a27329969ce8a99"},{"url":"https://git.kernel.org/stable/c/8f6976d635d190e3d7af7103daaa581cf1ccc12e"},{"url":"https://git.kernel.org/stable/c/9eeafcda1d6c11f0eec532243c4e96ec8c632bd7"},{"url":"https://git.kernel.org/stable/c/5a21e5114cec4cd3f8a2843d4c46bc49634d6e96"},{"url":"https://git.kernel.org/stable/c/2f17ca7ab5269ac2504e1039c3921373dccd7712"},{"url":"https://git.kernel.org/stable/c/a2e37d1ab773be3cd26b1c19593ca2dbcece9c57"},{"url":"https://git.kernel.org/stable/c/a64e2beb450179a5d43034af8d5476a11eac1486"},{"url":"https://git.kernel.org/stable/c/fdfb5cea4bf070cdb31d997efd87bb684df041fd"}],"title":"RDMA/cxgb4: free STAG index when TPT entry write fails","x_generator":{"engine":"bippy-1.2.0"}}}}