{"id":"CVE-2026-98014","published":"2026-09-25T11:17:29.767","lastModified":"2026-09-25T11:17:29.767","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: E-Switch, prevent mc_list repopulation during vport disable\n\nIn mlx5_esw_vport_disable(), move esw_apply_vport_rx_mode() ahead\nof esw_vport_change_handle_locked() so vport->allmulti_rule is\nNULL before the change handler observes it.\n\nDuring FW-fatal recovery the disable runs while dev->state ==\nINTERNAL_ERROR. The promisc query inside esw_update_vport_rx_mode()\nfails and returns early, leaving vport->allmulti_rule intact, so\nesw_update_vport_mc_promisc() runs and adds MLX5_ACTION_ADD entries\nto vport->mc_list whose flow rules are then installed in the FDB\nby esw_add_mc_addr(). esw_destroy_legacy_table() tears down the\nFDB with those refs still held, corrupting the sub-tree and\nleaving dangling flow_rule pointers in vport->mc_list.\n\nTwo-stage failure on `echo 1 > /sys/bus/pci/devices/<bdf>/reset`:\n\n  refcount_t: underflow; use-after-free.\n   tree_put_node+0xef/0x110 [mlx5_core]\n   clean_tree+0x44/0xd0 [mlx5_core] (x5)\n   mlx5_fs_core_cleanup+0x57/0x1c0 [mlx5_core]\n   mlx5_unload+0x65/0xd0 [mlx5_core]\n   ... mlx5_health_try_recover\n\n  BUG: unable to handle page fault for address: 0000000003000055\n   down_write+0x1c/0x60\n   mlx5_del_flow_rules+0x33/0x1f0 [mlx5_core]\n   esw_del_mc_addr+0x7b/0x170 [mlx5_core]\n   esw_apply_vport_addr_list+0x56/0xf0 [mlx5_core]\n   esw_vport_change_handle_locked+0x28b/0x310 [mlx5_core]\n   mlx5_esw_vport_enable+0x270/0x4a0 [mlx5_core]\n   ... mlx5_load ... mlx5_health_try_recover\n\nesw_apply_vport_rx_mode(false, false) clears vport->allmulti_rule\nvia its local state machine even when the FW del fails. With the\nrule NULL the !IS_ERR_OR_NULL(allmulti_rule) gate in the change\nhandler closes, no rules are installed during disable, and the\nreload starts with a clean mc_list.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/668e050429c7ca688cf4e7112f97f0cd269d446b","tags":[]},{"url":"https://git.kernel.org/stable/c/69904608e25e8ba58111aadd9210892cf3876201","tags":[]},{"url":"https://git.kernel.org/stable/c/72cfcb79026cffb6490f5044153a841d360b0cfc","tags":[]},{"url":"https://git.kernel.org/stable/c/c0c6f4ba8a37688f7b4d4044898d88f0450d44c2","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}