CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
In the Linux kernel, the following vulnerability has been resolved:
RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
MLX5IBMETHODDEVXSUBSCRIBEEVENT() links eventsub into sublist before initializing the fields used by the shared error path.
If eventfdctxfdget() then fails, the unwind path dereferences eventsub->evfile in uverbsuobjectput() and calls subscribeeventxadealloc() with an unset xakeylevel1.
subscribeeventxaalloc() creates the XA entry exactly once for a given keylevel1, on the first occurrence of that key. The unwind path must therefore call subscribeeventxadealloc() exactly once for it as well.
Enforce that by adding devxkeyinsublist() and calling subscribeeventxadealloc() only when the last matching pending entry is being cleaned up.