cbcvebase.
CVE-2026-45922
published 2026-05-27

CVE-2026-45922: In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler The…

medium5.5
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler The UVERBS_HANDLER(MLX5_IB_METHOD_GET_DATA_DIRECT_SYSFS_PATH) function allocates memory for the device path using kobject_get_path(). If the length of the device path exceeds the output buffer length, the function returns -ENOSPC but does not free the allocated memory, resulting in a memory leak. Add a kfree() call to the error path to ensure the allocated memory is properly freed. Compile tested only. Issue found using a prototype static analysis tool and code review.

Affected

6 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= ec7ad6530909983c8736c80af46e3529ce7bab55 < ee998cdbff6680891b0efd9d6ce53a388e5342c3ee998cdbff6680891b0efd9d6ce53a388e5342c3
linuxlinux>= ec7ad6530909983c8736c80af46e3529ce7bab55 < b2bc649c18fbe8a7fd38d17266da3dcbfbcc44d2b2bc649c18fbe8a7fd38d17266da3dcbfbcc44d2
linuxlinux>= ec7ad6530909983c8736c80af46e3529ce7bab55 < b3a10eca24fcfe913c0875e620f19596001bd6dcb3a10eca24fcfe913c0875e620f19596001bd6dc
linuxlinux>= ec7ad6530909983c8736c80af46e3529ce7bab55 < 9b9d253908478f504297ac283c514e5953ddafa69b9d253908478f504297ac283c514e5953ddafa6
linuxlinux_kernel