Database/Firmware, BMC & network fabric
Linux bnxt_en driver (RSS context delete logic): RSS contexts are not always freed in firmware when the driver deletes
Impact
RSS contexts are not always freed in firmware when the driver deletes them, leaving stale VNIC state on the adapter. Stale receive-steering state on a NIC is worth flagging in a multi-tenant context: RSS contexts and their VNICs determine which queues — and therefore which owner — receives which packets, and leaked contexts are exactly the kind of residue that should not survive a tenant teardown.
Who can reach it
Local, via repeated RSS context create/delete cycles from the host.
What to do
Kernel/driver upgrade plus host reboot. On bare-metal handoff, a cold power cycle of the NIC clears residual adapter state regardless of driver version — worth doing between tenants anyway.
References
Related entries
- Linux kernel Soft-RoCE shared receive queue (rdma_rxe, rxe_srq_from_init): If the copy_to_user() that returns the SRQCVE-2026-45852 · Linux kernel Soft-RoCE shared receive queue (rdma_rxe, rxe_srq_from_init)High
- Linux kernel (drivers/infiniband/sw/rxe): The soft-RoCE retransmit and ack timers race against queue-pair destructionCVE-2026-45910 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel RDS RDMA (memory-region cleanup on cookie copy failure): Once __rds_rdma_map() has handed theCVE-2026-46053 · Linux kernel RDS RDMA (memory-region cleanup on cookie copy failure)High
- Linux kernel (drivers/infiniband/hw/mana): The userspace ABI lets a tenant point several work queues at the sameCVE-2026-46117 · Linux kernel (drivers/infiniband/hw/mana)High
- Linux kernel (drivers/infiniband/hw/mana): The RSS hash-key length arrived from the userspace ABI structure and wentCVE-2026-46145 · Linux kernel (drivers/infiniband/hw/mana)High
- Linux kernel (drivers/infiniband/hw/mlx5): If the second of the two device-wide shared SRQs fails to allocate, theCVE-2026-46176 · Linux kernel (drivers/infiniband/hw/mlx5)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.