CVE-2026-74397

Source
https://cve.org/CVERecord?id=CVE-2026-74397
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74397.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74397
Downstream
Published
2026-08-15T05:59:09.329Z
Modified
2026-08-18T03:56:47.439540107Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier
Details

In the Linux kernel, the following vulnerability has been resolved:

IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier

mlx5iballoctransportdomain() allocates a transport domain and then may fail in mlx5ibenable_lb(). In that case, the allocated TD is leaked.

Fix this by deallocating the TD when mlx5ibenablelb() returns an error. Also return 0 explicitly in the no-loopback-capability success branch, and move dev->lb.mutex initialization to mlx5ibstageinit_init().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74397.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
146d2f1af3245a10b13eef263687e54f4e253d1d
Fixed
2c3b2667dad69d56774b79db763acb3a1bee0fc0
Fixed
37fc3cc0f924fd8d0f0cf87b92672dec75a32e57
Fixed
65e344925fa30abf50c8de8c150b397715fa2066
Fixed
f88e12c95fc19f719e06ca1e9eb20fdad68ef61a
Fixed
e79389115b9d27287ff6230a9750675106ed7668

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74397.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74397.json"