GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel ice: missing xa_destroy leaks xarray memory on every HW re-init

UnscoredCVE-2026-97979Kernel, userspace & hypervisorcurated

Impact

The ice driver for Intel E810-class 100G NICs added a sched_node_ids xarray to the port info structure and never called xa_destroy() on it, so the xarray's internal nodes leaked even after every element was removed. ice_init_hw() runs more than once in a node's life - devlink reload, and potentially after a DDP package load changes the Tx scheduler layout - so the leak accumulates on hosts where operators reload the NIC rather than reboot. The fix also moves the xarray from port_info into the hw structure to make its lifetime tractable. On a GPU node this is a slow kernel memory leak on the front-end NIC path, not a data or isolation issue; nothing in the record indicates a tenant-triggerable path. It was found by static analysis during unrelated work, not by an exploit.

Who can reach it

Requires privileged action on the host - a devlink reload or driver unload/reload of the ice interface. No unprivileged local or remote path in the record.

What to do

Update to a stable kernel carrying the xa_destroy() addition and the move of sched_node_ids into the hw struct, then drain and reboot the node. Until then, avoid repeated devlink reloads of ice interfaces on long-lived hosts. No fixed distro version is named in the record.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.