-

CVE-2026-98014

net/mlx5: E-Switch, prevent mc_list repopulation during vport disable

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5: E-Switch, prevent mc_list repopulation during vport disable

In mlx5_esw_vport_disable(), move esw_apply_vport_rx_mode() ahead
of esw_vport_change_handle_locked() so vport->allmulti_rule is
NULL before the change handler observes it.

During FW-fatal recovery the disable runs while dev->state ==
INTERNAL_ERROR. The promisc query inside esw_update_vport_rx_mode()
fails and returns early, leaving vport->allmulti_rule intact, so
esw_update_vport_mc_promisc() runs and adds MLX5_ACTION_ADD entries
to vport->mc_list whose flow rules are then installed in the FDB
by esw_add_mc_addr(). esw_destroy_legacy_table() tears down the
FDB with those refs still held, corrupting the sub-tree and
leaving dangling flow_rule pointers in vport->mc_list.

Two-stage failure on `echo 1 > /sys/bus/pci/devices/<bdf>/reset`:

  refcount_t: underflow; use-after-free.
   tree_put_node+0xef/0x110 [mlx5_core]
   clean_tree+0x44/0xd0 [mlx5_core] (x5)
   mlx5_fs_core_cleanup+0x57/0x1c0 [mlx5_core]
   mlx5_unload+0x65/0xd0 [mlx5_core]
   ... mlx5_health_try_recover

  BUG: unable to handle page fault for address: 0000000003000055
   down_write+0x1c/0x60
   mlx5_del_flow_rules+0x33/0x1f0 [mlx5_core]
   esw_del_mc_addr+0x7b/0x170 [mlx5_core]
   esw_apply_vport_addr_list+0x56/0xf0 [mlx5_core]
   esw_vport_change_handle_locked+0x28b/0x310 [mlx5_core]
   mlx5_esw_vport_enable+0x270/0x4a0 [mlx5_core]
   ... mlx5_load ... mlx5_health_try_recover

esw_apply_vport_rx_mode(false, false) clears vport->allmulti_rule
via its local state machine even when the FW del fails. With the
rule NULL the !IS_ERR_OR_NULL(allmulti_rule) gate in the change
handler closes, no rules are installed during disable, and the
reload starts with a clean mc_list.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4df1f2d36bdc9a368650bf14b9097c555e95f71d
Version < 413e04adcc1fd263cf02b1b83b4a0dbdc66bcee9
Status affected
Version 63546395a0e6ac264f78f65218086ce6014b4494
Version < 2196f9d3358b00fcb28835a5fde14071f51ecb96
Status affected
Version 922f56e9a795d6f3dd72d3428ebdd7ee040fa855
Version < 5a2b87dfceccf9065157a14a599d395c2b6281b8
Status affected
Version 922f56e9a795d6f3dd72d3428ebdd7ee040fa855
Version < 69904608e25e8ba58111aadd9210892cf3876201
Status affected
Version 922f56e9a795d6f3dd72d3428ebdd7ee040fa855
Version < 72cfcb79026cffb6490f5044153a841d360b0cfc
Status affected
Version 922f56e9a795d6f3dd72d3428ebdd7ee040fa855
Version < 668e050429c7ca688cf4e7112f97f0cd269d446b
Status affected
Version 922f56e9a795d6f3dd72d3428ebdd7ee040fa855
Version < c0c6f4ba8a37688f7b4d4044898d88f0450d44c2
Status affected
Version 18cead61e437f4c7898acca0a5f3df12f801d97f
Status affected
Version 6f5780536181d1d0d09a11a1bc92f22e143447e2
Status affected
Version 5.15.105
Version < 5.15.222
Status affected
Version 6.1.22
Version < 6.1.189
Status affected
Version 5.10.177
Version < 5.11
Status affected
Version 6.2.9
Version < 6.3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.3
Status affected
Version 0
Version < 6.3
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/69904608e25e8ba58111aadd9210892cf3876201
https://git.kernel.org/stable/c/72cfcb79026cffb6490f5044153a841d360b0cfc
https://git.kernel.org/stable/c/668e050429c7ca688cf4e7112f97f0cd269d446b
https://git.kernel.org/stable/c/c0c6f4ba8a37688f7b4d4044898d88f0450d44c2
https://git.kernel.org/stable/c/2196f9d3358b00fcb28835a5fde14071f51ecb96
https://git.kernel.org/stable/c/413e04adcc1fd263cf02b1b83b4a0dbdc66bcee9
https://git.kernel.org/stable/c/5a2b87dfceccf9065157a14a599d395c2b6281b8