PT-2026-104924 · Azure Linux · Kernel

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/counter: Fix num counters leak on bind qp failure in alloc and bind()
When rdma counter bind qp() fails in alloc and bind(), the error path jumps to err mode which frees the counter without decrementing port counter->num counters. The only place that decrements is rdma counter free(), which is unreachable since the counter was never successfully bound.
This leak accumulates across repeated failures, permanently preventing the port from switching to AUTO mode (-EBUSY in counter set mode()) and blocking the MANUAL→NONE auto-revert in rdma counter free(). When the mode was NONE before the call, the MANUAL mode set by counter set mode() also leaks since the revert logic is never reached.
Add an err bind label between the num counters increment and the existing err mode label. It decrements num counters and mirrors the MANUAL→NONE revert from rdma counter free(), ensuring the port state is fully restored on bind failure.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103781

Affected Products

Kernel