PT-2026-98553 · Linux · Linux
CVE-2026-97613
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: mana: Reserve extra CQ slot for the fence completion CQE
The RX completion queue is sized to hold exactly one CQE per posted RX WQE.
MANA FENCE RQ makes hardware post an additional CQE RX OBJECT FENCE after
the packet CQEs. The current sizing reserves no extra slot for it and in
rare cases, CQ has no guaranteed slot for the fence CQE when it is full of
packet CQEs. This can lead to dropping the fence completion while the
driver waits holding RTNL lock throughout the timeout duration.
Reserve one extra CQE slot for CQE RX OBJECT FENCE. mana gd alloc memory()
requires queue size to be a power-of-two and at least MANA PAGE SIZE;
the reservation pushes cq size past a power-of-two, so round up the CQ size
in mana create rxq().
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux