CVE-2026-80647: RDMA/hns: Fix warning in poll cq direct mode

Published Aug 28, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

RDMA/hns: Fix warning in poll cq direct mode

CQs allocated by iballoccq() always have a comphandler. Though in direct mode this handler is never expected to be called, it is still called when the driver is reset, triggering the following WARNONCE():

Call trace: ibcqcompletiondirect+0x38/0x60 hnsrocecqcompletion+0x54/0x90 (hnsrocehwv2] hnsrocehandledeviceerr+Ox1c8/0x340 [hnsrocehwv2] hnsrocehwv2uninitinstance.constprop.0+0x34/0x70 [hnsrocehwv2] hnsrocehwv2resetnotify+0xc4/0xe0 [hnsrocehwv2] hclgenotifyroceclient+0x60/0xbc [hclge] hclgeresetrebuild+0x48/0x34c [hclge] hclgeresetsubtask+0xcc/0xec [hclge] hclgeresetservicetask+0x80/0x160 [hclge] hclgeservicetask+0x50/0x80 (hclge] processonework+0x1cc/0x4d0 workerthread+0x154/0x414 kthread+0x104/0x144 retfromfork+0x10/0x18

Affected Software

1 affected component
Linux Linux kernel

Event History

Aug 28, 2026
CVE Published
via MITRE·06:48 AM
Data Sourced
via MITRE·06:48 AM
Description

Frequently Asked Questions

1

Which systems are affected by this warning?

The issue applies to Linux systems using the RDMA HNS RoCE driver with completion queues allocated through ib_alloc_cq() in direct polling mode. The warning is triggered when the driver is reset.

2

Does an attacker need to invoke the completion handler directly?

No attacker requirements are provided. The described trigger is a driver reset, during which the direct-mode completion handler is called even though it is not expected to run in that mode.

3

How can administrators identify the issue?

Check kernel logs for a WARN_ONCE call trace beginning with ib_cq_completion_direct and hns_roce_cq_completion, occurring during an HNS RoCE driver or device reset.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203