net/mlx5: E-Switch, prevent mc_list repopulation during vport disable
Summary
| CVE | CVE-2026-98014 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-25 11:17:29 UTC |
| Updated | 2026-09-25 11:17:29 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: E-Switch, prevent mc_list repopulation during vport disable In mlx5_esw_vport_disable(), move esw_apply_vport_rx_mode() ahead of esw_vport_change_handle_locked() so vport->allmulti_rule is NULL before the change handler observes it. During FW-fatal recovery the disable runs while dev->state == INTERNAL_ERROR. The promisc query inside esw_update_vport_rx_mode() fails and returns early, leaving vport->allmulti_rule intact, so esw_update_vport_mc_promisc() runs and adds MLX5_ACTION_ADD entries to vport->mc_list whose flow rules are then installed in the FDB by esw_add_mc_addr(). esw_destroy_legacy_table() tears down the FDB with those refs still held, corrupting the sub-tree and leaving dangling flow_rule pointers in vport->mc_list. Two-stage failure on `echo 1 > /sys/bus/pci/devices/<bdf>/reset`: refcount_t: underflow; use-after-free. tree_put_node+0xef/0x110 [mlx5_core] clean_tree+0x44/0xd0 [mlx5_core] (x5) mlx5_fs_core_cleanup+0x57/0x1c0 [mlx5_core] mlx5_unload+0x65/0xd0 [mlx5_core] ... mlx5_health_try_recover BUG: unable to handle page fault for address: 0000000003000055 down_write+0x1c/0x60 mlx5_del_flow_rules+0x33/0x1f0 [mlx5_core] esw_del_mc_addr+0x7b/0x170 [mlx5_core] esw_apply_vport_addr_list+0x56/0xf0 [mlx5_core] esw_vport_change_handle_locked+0x28b/0x310 [mlx5_core] mlx5_esw_vport_enable+0x270/0x4a0 [mlx5_core] ... mlx5_load ... mlx5_health_try_recover esw_apply_vport_rx_mode(false, false) clears vport->allmulti_rule via its local state machine even when the FW del fails. With the rule NULL the !IS_ERR_OR_NULL(allmulti_rule) gate in the change handler closes, no rules are installed during disable, and the reload starts with a clean mc_list. |
Risk And Classification
EPSS: 0.001680000 probability, percentile 0.053890000 (date 2026-09-27)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 922f56e9a795d6f3dd72d3428ebdd7ee040fa855 69904608e25e8ba58111aadd9210892cf3876201 git | Not specified |
| CNA | Linux | Linux | affected 922f56e9a795d6f3dd72d3428ebdd7ee040fa855 72cfcb79026cffb6490f5044153a841d360b0cfc git | Not specified |
| CNA | Linux | Linux | affected 922f56e9a795d6f3dd72d3428ebdd7ee040fa855 668e050429c7ca688cf4e7112f97f0cd269d446b git | Not specified |
| CNA | Linux | Linux | affected 922f56e9a795d6f3dd72d3428ebdd7ee040fa855 c0c6f4ba8a37688f7b4d4044898d88f0450d44c2 git | Not specified |
| CNA | Linux | Linux | affected 18cead61e437f4c7898acca0a5f3df12f801d97f git | Not specified |
| CNA | Linux | Linux | affected 4df1f2d36bdc9a368650bf14b9097c555e95f71d git | Not specified |
| CNA | Linux | Linux | affected 63546395a0e6ac264f78f65218086ce6014b4494 git | Not specified |
| CNA | Linux | Linux | affected 6f5780536181d1d0d09a11a1bc92f22e143447e2 git | Not specified |
| CNA | Linux | Linux | affected 5.10.177 5.11 semver | Not specified |
| CNA | Linux | Linux | affected 5.15.105 5.16 semver | Not specified |
| CNA | Linux | Linux | affected 6.1.22 6.2 semver | Not specified |
| CNA | Linux | Linux | affected 6.2.9 6.3 semver | Not specified |
| CNA | Linux | Linux | affected 6.3 | Not specified |
| CNA | Linux | Linux | unaffected 6.3 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.111 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.53 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.7 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc3 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/72cfcb79026cffb6490f5044153a841d360b0cfc | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c0c6f4ba8a37688f7b4d4044898d88f0450d44c2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/69904608e25e8ba58111aadd9210892cf3876201 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/668e050429c7ca688cf4e7112f97f0cd269d446b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.