CVE-2026-98014
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: E-Switch, prevent mc_list repopulation during vport disable
In mlx5_esw_vport_disable(), move esw_apply_vport_rx_mode() ahead of esw_vport_change_handle_locked() so vport->allmulti_rule is NULL before the change handler observes it.
During FW-fatal recovery the disable runs while dev->state == INTERNAL_ERROR. The promisc query inside esw_update_vport_rx_mode() fails and returns early, leaving vport->allmulti_rule intact, so esw_update_vport_mc_promisc() runs and adds MLX5_ACTION_ADD entries to vport->mc_list whose flow rules are then installed in the FDB by esw_add_mc_addr(). esw_destroy_legacy_table() tears down the FDB with those refs still held, corrupting the sub-tree and leaving dangling flow_rule pointers in vport->mc_list.
Leer descripción completaMostrar menos
Two-stage failure on `echo 1 > /sys/bus/pci/devices/<bdf>/reset`:
esw_apply_vport_rx_mode(false, false) clears vport->allmulti_rule via its local state machine even when the FW del fails. With the rule NULL the !IS_ERR_OR_NULL(allmulti_rule) gate in the change handler closes, no rules are installed during disable, and the reload starts with a clean mc_list.
Detalles técnicos trazas, registros y código del informe original
refcount_t: underflow; use-after-free. tree_put_node+0xef/0x110 [mlx5_core] clean_tree+0x44/0xd0 [mlx5_core] (x5) mlx5_fs_core_cleanup+0x57/0x1c0 [mlx5_core] mlx5_unload+0x65/0xd0 [mlx5_core] ... mlx5_health_try_recover BUG: unable to handle page fault for address: 0000000003000055 down_write+0x1c/0x60 mlx5_del_flow_rules+0x33/0x1f0 [mlx5_core] esw_del_mc_addr+0x7b/0x170 [mlx5_core] esw_apply_vport_addr_list+0x56/0xf0 [mlx5_core] esw_vport_change_handle_locked+0x28b/0x310 [mlx5_core] mlx5_esw_vport_enable+0x270/0x4a0 [mlx5_core] ... mlx5_load ... mlx5_health_try_recover
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/2196f9d3358b00fcb28835a5fde14071f51ecb96
- https://git.kernel.org/stable/c/413e04adcc1fd263cf02b1b83b4a0dbdc66bcee9
- https://git.kernel.org/stable/c/5a2b87dfceccf9065157a14a599d395c2b6281b8
- https://git.kernel.org/stable/c/668e050429c7ca688cf4e7112f97f0cd269d446b
- https://git.kernel.org/stable/c/69904608e25e8ba58111aadd9210892cf3876201
- https://git.kernel.org/stable/c/72cfcb79026cffb6490f5044153a841d360b0cfc
- https://git.kernel.org/stable/c/c0c6f4ba8a37688f7b4d4044898d88f0450d44c2
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98014",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4df1f2d36bdc9a368650bf14b9097c555e95f71d",
"lessThan": "413e04adcc1fd263cf02b1b83b4a0dbdc66bcee9",
"versionType": "git"
},
{
"status": "affected",
"version": "63546395a0e6ac264f78f65218086ce6014b4494",
"lessThan": "2196f9d3358b00fcb28835a5fde14071f51ecb96",
"versionType": "git"
},
{
"status": "affected",
"version": "922f56e9a795d6f3dd72d3428ebdd7ee040fa855",
"lessThan": "5a2b87dfceccf9065157a14a599d395c2b6281b8",
"versionType": "git"
},
{
"status": "affected",
"version": "922f56e9a795d6f3dd72d3428ebdd7ee040fa855",
"lessThan": "69904608e25e8ba58111aadd9210892cf3876201",
"versionType": "git"
},
{
"status": "affected",
"version": "922f56e9a795d6f3dd72d3428ebdd7ee040fa855",
"lessThan": "72cfcb79026cffb6490f5044153a841d360b0cfc",
"versionType": "git"
},
{
"status": "affected",
"version": "922f56e9a795d6f3dd72d3428ebdd7ee040fa855",
"lessThan": "668e050429c7ca688cf4e7112f97f0cd269d446b",
"versionType": "git"
},
{
"status": "affected",
"version": "922f56e9a795d6f3dd72d3428ebdd7ee040fa855",
"lessThan": "c0c6f4ba8a37688f7b4d4044898d88f0450d44c2",
"versionType": "git"
},
{
"status": "affected",
"version": "18cead61e437f4c7898acca0a5f3df12f801d97f",
"versionType": "git"
},
{
"status": "affected",
"version": "6f5780536181d1d0d09a11a1bc92f22e143447e2",
"versionType": "git"
},
{
"status": "affected",
"version": "5.15.105",
"lessThan": "5.15.222",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.22",
"lessThan": "6.1.189",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.10.177",
"lessThan": "5.11",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.2.9",
"lessThan": "6.3",
"versionType": "semver"
}
],
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/eswitch.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/eswitch.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:29.767",
"references": [
{
"url": "https://git.kernel.org/stable/c/2196f9d3358b00fcb28835a5fde14071f51ecb96",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/413e04adcc1fd263cf02b1b83b4a0dbdc66bcee9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5a2b87dfceccf9065157a14a599d395c2b6281b8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/668e050429c7ca688cf4e7112f97f0cd269d446b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/69904608e25e8ba58111aadd9210892cf3876201",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/72cfcb79026cffb6490f5044153a841d360b0cfc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c0c6f4ba8a37688f7b4d4044898d88f0450d44c2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: E-Switch, prevent mc_list repopulation during vport disable\n\nIn mlx5_esw_vport_disable(), move esw_apply_vport_rx_mode() ahead\nof esw_vport_change_handle_locked() so vport->allmulti_rule is\nNULL before the change handler observes it.\n\nDuring FW-fatal recovery the disable runs while dev->state ==\nINTERNAL_ERROR. The promisc query inside esw_update_vport_rx_mode()\nfails and returns early, leaving vport->allmulti_rule intact, so\nesw_update_vport_mc_promisc() runs and adds MLX5_ACTION_ADD entries\nto vport->mc_list whose flow rules are then installed in the FDB\nby esw_add_mc_addr(). esw_destroy_legacy_table() tears down the\nFDB with those refs still held, corrupting the sub-tree and\nleaving dangling flow_rule pointers in vport->mc_list.\n\nTwo-stage failure on `echo 1 > /sys/bus/pci/devices/<bdf>/reset`:\n\n refcount_t: underflow; use-after-free.\n tree_put_node+0xef/0x110 [mlx5_core]\n clean_tree+0x44/0xd0 [mlx5_core] (x5)\n mlx5_fs_core_cleanup+0x57/0x1c0 [mlx5_core]\n mlx5_unload+0x65/0xd0 [mlx5_core]\n ... mlx5_health_try_recover\n\n BUG: unable to handle page fault for address: 0000000003000055\n down_write+0x1c/0x60\n mlx5_del_flow_rules+0x33/0x1f0 [mlx5_core]\n esw_del_mc_addr+0x7b/0x170 [mlx5_core]\n esw_apply_vport_addr_list+0x56/0xf0 [mlx5_core]\n esw_vport_change_handle_locked+0x28b/0x310 [mlx5_core]\n mlx5_esw_vport_enable+0x270/0x4a0 [mlx5_core]\n ... mlx5_load ... mlx5_health_try_recover\n\nesw_apply_vport_rx_mode(false, false) clears vport->allmulti_rule\nvia its local state machine even when the FW del fails. With the\nrule NULL the !IS_ERR_OR_NULL(allmulti_rule) gate in the change\nhandler closes, no rules are installed during disable, and the\nreload starts with a clean mc_list."
}
],
"lastModified": "2026-10-03T11:18:24.517",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}