0.0
NA
CVE-2026-74397
IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier
Description

In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier mlx5_ib_alloc_transport_domain() allocates a transport domain and then may fail in mlx5_ib_enable_lb(). In that case, the allocated TD is leaked. Fix this by deallocating the TD when mlx5_ib_enable_lb() returns an error. Also return 0 explicitly in the no-loopback-capability success branch, and move dev->lb.mutex initialization to mlx5_ib_stage_init_init().

INFO

Published Date :

Aug. 15, 2026, 6:22 a.m.

Last Modified :

Aug. 15, 2026, 6:22 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-74397 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Fix transport-domain rollback issue by deallocating TD on error.
  • Deallocate transport domain on mlx5_ib_enable_lb() error.
  • Return 0 in no-loopback-capability success branch.
  • Initialize dev->lb.mutex earlier in mlx5_ib_stage_init_init().
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-74397 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-74397 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-74397 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-74397 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 15, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '146d2f1af3245a10b13eef263687e54f4e253d1d', 'lessThan': '2c3b2667dad69d56774b79db763acb3a1bee0fc0', 'versionType': 'git'}, {'status': 'affected', 'version': '146d2f1af3245a10b13eef263687e54f4e253d1d', 'lessThan': '37fc3cc0f924fd8d0f0cf87b92672dec75a32e57', 'versionType': 'git'}, {'status': 'affected', 'version': '146d2f1af3245a10b13eef263687e54f4e253d1d', 'lessThan': '65e344925fa30abf50c8de8c150b397715fa2066', 'versionType': 'git'}, {'status': 'affected', 'version': '146d2f1af3245a10b13eef263687e54f4e253d1d', 'lessThan': 'f88e12c95fc19f719e06ca1e9eb20fdad68ef61a', 'versionType': 'git'}, {'status': 'affected', 'version': '146d2f1af3245a10b13eef263687e54f4e253d1d', 'lessThan': 'e79389115b9d27287ff6230a9750675106ed7668', 'versionType': 'git'}], 'programFiles': ['drivers/infiniband/hw/mlx5/main.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.5'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.5', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/infiniband/hw/mlx5/main.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier mlx5_ib_alloc_transport_domain() allocates a transport domain and then may fail in mlx5_ib_enable_lb(). In that case, the allocated TD is leaked. Fix this by deallocating the TD when mlx5_ib_enable_lb() returns an error. Also return 0 explicitly in the no-loopback-capability success branch, and move dev->lb.mutex initialization to mlx5_ib_stage_init_init().
    Added Reference https://git.kernel.org/stable/c/2c3b2667dad69d56774b79db763acb3a1bee0fc0
    Added Reference https://git.kernel.org/stable/c/37fc3cc0f924fd8d0f0cf87b92672dec75a32e57
    Added Reference https://git.kernel.org/stable/c/65e344925fa30abf50c8de8c150b397715fa2066
    Added Reference https://git.kernel.org/stable/c/e79389115b9d27287ff6230a9750675106ed7668
    Added Reference https://git.kernel.org/stable/c/f88e12c95fc19f719e06ca1e9eb20fdad68ef61a
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.