{"api_version":"1","generated_at":"2026-09-26T20:44:26+00:00","cve":"CVE-2026-97962","urls":{"html":"https://cve.report/CVE-2026-97962","api":"https://cve.report/api/cve/CVE-2026-97962.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-97962","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-97962"},"summary":{"title":"net/mlx5e: Move representor vnic reporter to eswitch devlink port","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Move representor vnic reporter to eswitch devlink port\n\nThe representor vnic devlink health reporter is created and destroyed\nalong the representor netdev (un)load path, which is not serialized by\nthe devlink instance lock. Destroying the reporter from there triggers\na devl_assert_locked() splat on driver unbind:\n  WARNING: net/devlink/core.c:259 at devl_assert_locked+0x54/0x70, CPU#2: bash/3758\n  Modules linked in: mlx5_vdpa vringh vdpa mlx5_ib mlx5_fwctl mlx5_core ...\n  CPU: 2 UID: 0 PID: 3758 Comm: bash Tainted: G        W           6.19.0+ #1 PREEMPT\n  Tainted: [W]=WARN\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), ...\n  RIP: 0010:devl_assert_locked+0x54/0x70\n  Call Trace:\n   <TASK>\n   devl_health_reporter_destroy+0x3a/0x1b0\n   mlx5e_vport_rep_unload+0x12d/0x2b0 [mlx5_core]\n   mlx5_eswitch_unregister_vport_reps+0x1b8/0x220 [mlx5_core]\n   ? __esw_offloads_unload_rep+0x190/0x190 [mlx5_core]\n   ? kernfs_remove_by_name_ns+0xc3/0xf0\n   device_release_driver_internal+0x3b2/0x560\n   unbind_store+0xce/0xf0\n\nMove the reporter's lifecycle to the eswitch devlink port (un)register\npaths, which are already serialized by the devlink instance lock, and\nstore the handle on mlx5_devlink_port. Use the port's mlx5_vport as the\nreporter priv since the diagnose callback only needs a device handle and\na vport number, and mlx5_vport carries both and is initialized before\nany representor driver probes.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-25 11:17:23","updated_at":"2026-09-25 11:17:23"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/7f26a5e8040b4957ef4dbdfcde6cc7ba2db53937","name":"https://git.kernel.org/stable/c/7f26a5e8040b4957ef4dbdfcde6cc7ba2db53937","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d1fcff9b39bac188ef62a77ebd176484be928ec2","name":"https://git.kernel.org/stable/c/d1fcff9b39bac188ef62a77ebd176484be928ec2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/dcaba72c85c14fe7393a59d61695941e6ccbd7d7","name":"https://git.kernel.org/stable/c/dcaba72c85c14fe7393a59d61695941e6ccbd7d7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97962","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97962","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cf14af140a5ad0937d385ce693100f33f02e9c54 dcaba72c85c14fe7393a59d61695941e6ccbd7d7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cf14af140a5ad0937d385ce693100f33f02e9c54 d1fcff9b39bac188ef62a77ebd176484be928ec2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cf14af140a5ad0937d385ce693100f33f02e9c54 7f26a5e8040b4957ef4dbdfcde6cc7ba2db53937 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.4","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.4 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.7 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc3 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en_rep.c","drivers/net/ethernet/mellanox/mlx5/core/en_rep.h","drivers/net/ethernet/mellanox/mlx5/core/esw/devlink_port.c","drivers/net/ethernet/mellanox/mlx5/core/eswitch.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"dcaba72c85c14fe7393a59d61695941e6ccbd7d7","status":"affected","version":"cf14af140a5ad0937d385ce693100f33f02e9c54","versionType":"git"},{"lessThan":"d1fcff9b39bac188ef62a77ebd176484be928ec2","status":"affected","version":"cf14af140a5ad0937d385ce693100f33f02e9c54","versionType":"git"},{"lessThan":"7f26a5e8040b4957ef4dbdfcde6cc7ba2db53937","status":"affected","version":"cf14af140a5ad0937d385ce693100f33f02e9c54","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en_rep.c","drivers/net/ethernet/mellanox/mlx5/core/en_rep.h","drivers/net/ethernet/mellanox/mlx5/core/esw/devlink_port.c","drivers/net/ethernet/mellanox/mlx5/core/eswitch.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.4"},{"lessThan":"6.4","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.7","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc3","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","versionStartIncluding":"6.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.7","versionStartIncluding":"6.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc3","versionStartIncluding":"6.4","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Move representor vnic reporter to eswitch devlink port\n\nThe representor vnic devlink health reporter is created and destroyed\nalong the representor netdev (un)load path, which is not serialized by\nthe devlink instance lock. Destroying the reporter from there triggers\na devl_assert_locked() splat on driver unbind:\n  WARNING: net/devlink/core.c:259 at devl_assert_locked+0x54/0x70, CPU#2: bash/3758\n  Modules linked in: mlx5_vdpa vringh vdpa mlx5_ib mlx5_fwctl mlx5_core ...\n  CPU: 2 UID: 0 PID: 3758 Comm: bash Tainted: G        W           6.19.0+ #1 PREEMPT\n  Tainted: [W]=WARN\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), ...\n  RIP: 0010:devl_assert_locked+0x54/0x70\n  Call Trace:\n   <TASK>\n   devl_health_reporter_destroy+0x3a/0x1b0\n   mlx5e_vport_rep_unload+0x12d/0x2b0 [mlx5_core]\n   mlx5_eswitch_unregister_vport_reps+0x1b8/0x220 [mlx5_core]\n   ? __esw_offloads_unload_rep+0x190/0x190 [mlx5_core]\n   ? kernfs_remove_by_name_ns+0xc3/0xf0\n   device_release_driver_internal+0x3b2/0x560\n   unbind_store+0xce/0xf0\n\nMove the reporter's lifecycle to the eswitch devlink port (un)register\npaths, which are already serialized by the devlink instance lock, and\nstore the handle on mlx5_devlink_port. Use the port's mlx5_vport as the\nreporter priv since the diagnose callback only needs a device handle and\na vport number, and mlx5_vport carries both and is initialized before\nany representor driver probes."}],"providerMetadata":{"dateUpdated":"2026-09-25T10:23:06.150Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/dcaba72c85c14fe7393a59d61695941e6ccbd7d7"},{"url":"https://git.kernel.org/stable/c/d1fcff9b39bac188ef62a77ebd176484be928ec2"},{"url":"https://git.kernel.org/stable/c/7f26a5e8040b4957ef4dbdfcde6cc7ba2db53937"}],"title":"net/mlx5e: Move representor vnic reporter to eswitch devlink port","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-97962","datePublished":"2026-09-25T10:23:06.150Z","dateReserved":"2026-09-25T10:18:58.206Z","dateUpdated":"2026-09-25T10:23:06.150Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-25 11:17:23","lastModifiedDate":"2026-09-25 11:17:23","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"97962","Ordinal":"1","Title":"net/mlx5e: Move representor vnic reporter to eswitch devlink por","CVE":"CVE-2026-97962","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"97962","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Move representor vnic reporter to eswitch devlink port\n\nThe representor vnic devlink health reporter is created and destroyed\nalong the representor netdev (un)load path, which is not serialized by\nthe devlink instance lock. Destroying the reporter from there triggers\na devl_assert_locked() splat on driver unbind:\n  WARNING: net/devlink/core.c:259 at devl_assert_locked+0x54/0x70, CPU#2: bash/3758\n  Modules linked in: mlx5_vdpa vringh vdpa mlx5_ib mlx5_fwctl mlx5_core ...\n  CPU: 2 UID: 0 PID: 3758 Comm: bash Tainted: G        W           6.19.0+ #1 PREEMPT\n  Tainted: [W]=WARN\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), ...\n  RIP: 0010:devl_assert_locked+0x54/0x70\n  Call Trace:\n   <TASK>\n   devl_health_reporter_destroy+0x3a/0x1b0\n   mlx5e_vport_rep_unload+0x12d/0x2b0 [mlx5_core]\n   mlx5_eswitch_unregister_vport_reps+0x1b8/0x220 [mlx5_core]\n   ? __esw_offloads_unload_rep+0x190/0x190 [mlx5_core]\n   ? kernfs_remove_by_name_ns+0xc3/0xf0\n   device_release_driver_internal+0x3b2/0x560\n   unbind_store+0xce/0xf0\n\nMove the reporter's lifecycle to the eswitch devlink port (un)register\npaths, which are already serialized by the devlink instance lock, and\nstore the handle on mlx5_devlink_port. Use the port's mlx5_vport as the\nreporter priv since the diagnose callback only needs a device handle and\na vport number, and mlx5_vport carries both and is initialized before\nany representor driver probes.","Type":"Description","Title":"net/mlx5e: Move representor vnic reporter to eswitch devlink por"}]}}}