In the Linux kernel, the following vulnerability has been resolved:
RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
MLX5IBMETHODDEVXSUBSCRIBEEVENT() links eventsub into sub_list before initializing the fields used by the shared error path.
If eventfdctxfdget() then fails, the unwind path dereferences eventsub->evfile in uverbsuobjectput() and calls subscribeeventxadealloc() with an unset xakey_level1.
subscribeeventxaalloc() creates the XA entry exactly once for a given keylevel1, on the first occurrence of that key. The unwind path must therefore call subscribeeventxa_dealloc() exactly once for it as well.
Enforce that by adding devxkeyinsublist() and calling subscribeeventxa_dealloc() only when the last matching pending entry is being cleaned up.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74395.json"
}