NVIDIA/Mellanox ConnectX driver (mlx5_ib user access region index release): The driver released the software-side UAR
Impact
The driver released the software-side UAR index rather than the index the hardware actually handed back. User access regions are the doorbell pages the driver maps into each tenant's address space; returning the wrong index to the allocator desynchronises the allocator from the hardware, so an index still owned by one context can be handed to the next one that asks. Two tenants sharing a doorbell page is a direct isolation failure on the ConnectX adapter, not merely a leak.
Who can reach it
Local. Occurs on the ordinary allocate/free cycle of RDMA user contexts, so a tenant that repeatedly creates and destroys contexts drives the desynchronisation.
What to do
Kernel update freeing the hardware-provided UAR index. Nothing to tune - patch and reboot. The kernel CNA record is terse on exploitation detail; treat the doorbell-aliasing consequence described here as the operator-facing reading of the fix, and confirm against your own driver version before ranking it.
References
Related entries
- Linux kernel amdgpu RAS / GPU reset and recovery path (drm/amdgpu): An out-of-bounds access in the amdgpu RAS / GPUCVE-2026-74357 · Linux kernel amdgpu RAS / GPU reset and recovery path (drm/amdgpu)High
- Linux kernel vmwgfx: undersized DRAW_PRIMITIVES header wraps the bound into an out-of-bounds readCVE-2026-74444 · Linux kernel drm/vmwgfx (vmw_cmd_draw DRAW_PRIMITIVES header size)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2026-74449 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux kernel amdgpu power management (SMU/powerplay) (drm/amd/pm): A use-after-free in the amdgpu power managementCVE-2026-74450 · Linux kernel amdgpu power management (SMU/powerplay) (drm/amd/pm)High
- Linux kernel drm_gem_shmem: PMD huge-page fault can map past the VMA end and trip VM_BUG_ONCVE-2026-80582 · Linux kernel DRM GEM shmem helper (drm_gem_shmem ->huge_fault PMD path)High
- Linux kernel drm/xe: userptr inject path takes notifier_lock for read, tripping a GPU SVM lock assertionCVE-2026-80606 · Linux kernel drm/xe userptr (notifier_lock held for read on the invalidation-inject path)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.