CVE-2026-74299

Source
https://cve.org/CVERecord?id=CVE-2026-74299
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74299.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74299
Downstream
Published
2026-08-15T05:58:02.688Z
Modified
2026-08-16T03:48:48.308402065Z
Summary
RDMA/core: Fix FRMR aging push to queue error flow
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/core: Fix FRMR aging push to queue error flow

Aging pools with pinned handles requires moving handles from the active queue to a non-empty inactive queue that might fail on new page allocation, we are currently not handling the fault and leaking any mkey that fails the push.

Fix by Introducing pushqueuetoqueuelocked() that fills the destination's partial tail page from the source and then splices the remaining source pages onto the destination, performing no allocation.

Replace the per-handle move loop in agepinnedpool() and the open-coded splice in poolagingwork() with calls to the helper. As the helper cannot fail under memory pressure, removing a class of GFP_ATOMIC allocations under the pool lock and simplifying the error flow.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74299.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
020d189d16a62ed56115cce7e255459cf0eeb4e6
Fixed
edf133d28fc43f7f8b0da43a8d5b93fdf8073d35
Fixed
c6936506ed556ce3ccad36ab999baf2764dd7d25

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74299.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74299.json"