Database/Kernel, userspace & hypervisor
Linux kernel ice: missing xa_destroy leaks xarray memory on every HW re-init
Impact
The ice driver for Intel E810-class 100G NICs added a sched_node_ids xarray to the port info structure and never called xa_destroy() on it, so the xarray's internal nodes leaked even after every element was removed. ice_init_hw() runs more than once in a node's life - devlink reload, and potentially after a DDP package load changes the Tx scheduler layout - so the leak accumulates on hosts where operators reload the NIC rather than reboot. The fix also moves the xarray from port_info into the hw structure to make its lifetime tractable. On a GPU node this is a slow kernel memory leak on the front-end NIC path, not a data or isolation issue; nothing in the record indicates a tenant-triggerable path. It was found by static analysis during unrelated work, not by an exploit.
Who can reach it
Requires privileged action on the host - a devlink reload or driver unload/reload of the ice interface. No unprivileged local or remote path in the record.
What to do
Update to a stable kernel carrying the xa_destroy() addition and the move of sched_node_ids into the hw struct, then drain and reboot the node. Until then, avoid repeated devlink reloads of ice interfaces on long-lived hosts. No fixed distro version is named in the record.
References
Related entries
- Linux kernel vhost-vdpa: failed eventfd install leaves an ERR_PTR reachable by the config callbackCVE-2026-97993 · Linux kernel vhost-vdpa (ERR_PTR installed in v->config_ctx by VHOST_VDPA_SET_CONFIG_CALL)Unscored
- Linux kernel vhost-vdpa: queue size is not checked against the device maximum, giving an out-of-bounds descriptor readCVE-2026-97994 · Linux kernel vhost-vdpa (VHOST_SET_VRING_NUM validation)Unscored
- Linux kernel BPF verifier (bpf_loop nr_loops argument type): bpf_loop() declared nr_loops as ARG_ANYTHING, so aCVE-2026-98007 · Linux kernel BPF verifier (bpf_loop nr_loops argument type)Unscored
- Linux kernel BPF: bpf_btf_find_by_name_kind() can sleep in softirq context and install an fd into the interrupted taskCVE-2026-98046 · Linux kernel BPF helper bpf_btf_find_by_name_kind() (missing sleepable annotation)Unscored
- Linux kernel BPF: bpf_snprintf_btf() on a BTF_KIND_VAR from base BTF NULL-derefs in btf_var_show()CVE-2026-98063 · Linux kernel BPF BTF display (btf_var_show() unguarded resolved_ids deref)Unscored
- Linux kernel BPF: rendering a "const void" BTF type through bpf_snprintf_btf() NULL-derefs a missing show opCVE-2026-98064 · Linux kernel BPF BTF display (btf_modifier_show() missing show op for void)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.