Back

MEDIUM

net/mlx5: HWS, fix matcher leak on resize target setup failure

Published Aug 15, 2026

Description

hws_bwc_matcher_move() allocates a replacement matcher before setting it as the resize target. If mlx5hws_matcher_resize_set_target() fails, the replacement matcher is not attached anywhere and is leaked.

Fix the leak by destroying the replacement matcher before returning from the resize-target failure path.

The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1.

An x86_64 allyesconfig build showed no new warnings. As we do not have a mlx5 HWS-capable device to test with, no runtime testing was able to be performed.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Aug 15, 2026
Updated Aug 17, 2026
Reserved Aug 9, 2026

CISA Vulnrichment

No data

NVD

Status Received
Modified Aug 17, 2026

Red Hat

Severity Low
Public date Aug 15, 2026
Bugzilla 2516265

ENISA EUVD

Assigner Linux
Published Aug 15, 2026
Updated Aug 17, 2026

GitHub

No data