-
CVE-2026-98074
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:24:13
- Zuletzt bearbeitet 03.10.2026 11:18:28
- Erkennungen
bonding: do not clear curr_active_slave prematurely when releasing all slaves
In the Linux kernel, the following vulnerability has been resolved: bonding: do not clear curr_active_slave prematurely when releasing all slaves When releasing all slaves during bond destruction (all == true), __bond_release_one() unconditionally clears bond->curr_active_slave to NULL in every iteration. If a backup slave is released before the active slave, bond_alb_deinit_slave() triggers rlb_teach_disabled_mac_on_primary(), which increments the active slave dev promiscuity counter and sets bond_info->primary_is_promisc = 1. Because bond->curr_active_slave was prematurely cleared to NULL when releasing the backup slave, the subsequent iteration releasing the active slave evaluates oldcurrent as NULL, so bond_change_active_slave(bond, NULL) is skipped. Consequently, bond_alb_handle_active_change() is never called to decrement the promiscuity counter, permanently leaking promiscuous mode on the physical device after bond teardown. When oldcurrent == slave, bond_change_active_slave(bond, NULL) already sets bond->curr_active_slave to NULL. We only need to avoid selecting a new active slave when all == true. Replace the if (all) branch with if (!all && oldcurrent == slave).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
0896341a44bf04bf6149d9307fe4686006f3eee1
Version <
b1ded242135071769902778dbab081e3fc09730f
Status
affected
Version
0896341a44bf04bf6149d9307fe4686006f3eee1
Version <
e39b203ec9e73852098d41b26386172d51babeb9
Status
affected
Version
0896341a44bf04bf6149d9307fe4686006f3eee1
Version <
384739c631aa6749356ba062d6b7c9a484a733f6
Status
affected
Version
0896341a44bf04bf6149d9307fe4686006f3eee1
Version <
7b435c69a30b40efc642de98b9bfa95fcf2ad4f0
Status
affected
Version
0896341a44bf04bf6149d9307fe4686006f3eee1
Version <
d6ef22e79c2be3612868daede0e9a84f05439d9e
Status
affected
Version
0896341a44bf04bf6149d9307fe4686006f3eee1
Version <
19ba7ecfade159b3702c78a360fd7d971e2b7109
Status
affected
Version
0896341a44bf04bf6149d9307fe4686006f3eee1
Version <
6d0ee411d5437f3d126ea6979acb83a8da29dc81
Status
affected
Version
0896341a44bf04bf6149d9307fe4686006f3eee1
Version <
af602c7aa5fedc9be3043244017aef4f26c96b70
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.9
Status
affected
Version
0
Version <
3.9
Status
unaffected
Version <=
5.10.*
Version
5.10.271
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.054 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/d6ef22e79c2be3612868daede0e9a84f05439d9e
https://git.kernel.org/stable/c/19ba7ecfade159b3702c78a360fd7d971e2b7109
https://git.kernel.org/stable/c/6d0ee411d5437f3d126ea6979acb83a8da29dc81
https://git.kernel.org/stable/c/af602c7aa5fedc9be3043244017aef4f26c96b70
https://git.kernel.org/stable/c/384739c631aa6749356ba062d6b7c9a484a733f6
https://git.kernel.org/stable/c/7b435c69a30b40efc642de98b9bfa95fcf2ad4f0
https://git.kernel.org/stable/c/b1ded242135071769902778dbab081e3fc09730f
https://git.kernel.org/stable/c/e39b203ec9e73852098d41b26386172d51babeb9