SB20260113120 - Improper resource shutdown or release in Linux kernel infiniband core driver
Published: January 13, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2025-71084)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to failure to properly release resources within the destroy_mc() function in drivers/infiniband/core/cma.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3ba6d01c4b3c584264dc733c6a2ecc5bbc8e0bb5
- https://git.kernel.org/stable/c/57f3cb6c84159d12ba343574df2115fb18dd83ca
- https://git.kernel.org/stable/c/5cb34bb5fd726491b809efbeb5cfd63ae5bf9cf3
- https://git.kernel.org/stable/c/ab668a58c4a2ccb6d54add7a76f2f955d15d0196
- https://git.kernel.org/stable/c/c0acdee513239e1d6e1b490f56be0e6837dfd162