CVE-2026-23289 — Missing Release of Resource after Effective Lifetime in Linux
Severity
7.1HIGH
No vectorEPSS
0.0%
top 90.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 25
Description
In the Linux kernel, the following vulnerability has been resolved:
IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq()
Fix a user triggerable leak on the system call failure path.
Affected Packages3 packages
▶CVEListV5linux/linuxec34a922d243c3401a694450734e9effb2bafbfe — f67f1ad4029e9fa183141546de31987b254c9292+6
🔴Vulnerability Details
4OSV▶
CVE-2026-23289: In the Linux kernel, the following vulnerability has been resolved: IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq() Fix a user trigg↗2026-03-25
GHSA▶
GHSA-gwxh-wqjf-9572: In the Linux kernel, the following vulnerability has been resolved:
IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq()
Fix a user tri↗2026-03-25