{"id":"CVE-2026-98014","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: E-Switch, prevent mc_list repopulation during vport disable\n\nIn mlx5_esw_vport_disable(), move esw_apply_vport_rx_mode() ahead\nof esw_vport_change_handle_lock…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: E-Switch, prevent mc_list repopulation during vport disable\n\nIn mlx5_esw_vport_disable(), move esw_apply_vport_rx_mode() ahead\nof esw_vport_change_handle_lock…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 922f56e9a795d6f3dd72d3428ebdd7ee040fa855 < 69904608e25e8ba58111aadd9210892cf3876201","Linux >= 922f56e9a795d6f3dd72d3428ebdd7ee040fa855 < 72cfcb79026cffb6490f5044153a841d360b0cfc","Linux >= 922f56e9a795d6f3dd72d3428ebdd7ee040fa855 < 668e050429c7ca688cf4e7112f97f0cd269d446b","Linux >= 922f56e9a795d6f3dd72d3428ebdd7ee040fa855 < c0c6f4ba8a37688f7b4d4044898d88f0450d44c2","Linux 18cead61e437f4c7898acca0a5f3df12f801d97f","Linux 4df1f2d36bdc9a368650bf14b9097c555e95f71d","Linux 63546395a0e6ac264f78f65218086ce6014b4494","Linux 6f5780536181d1d0d09a11a1bc92f22e143447e2","Linux >= 5.10.177 < 5.11","Linux >= 5.15.105 < 5.16","Linux >= 6.1.22 < 6.2","Linux >= 6.2.9 < 6.3","Linux 6.3"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T11:17:29.767","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98014","references":[{"url":"https://git.kernel.org/stable/c/668e050429c7ca688cf4e7112f97f0cd269d446b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/69904608e25e8ba58111aadd9210892cf3876201","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/72cfcb79026cffb6490f5044153a841d360b0cfc","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0c6f4ba8a37688f7b4d4044898d88f0450d44c2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T11:06:38.857Z","slug":"CVE-2026-98014","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: E-Switch, prevent mc_list repopulation during vport disable\n\nIn mlx5_esw_vport_disable(), move esw_apply_vport_rx_mode() ahead\nof esw_vport_change_handle_locked() so vport->allmulti_rule is\nNULL before the change handler observes it.\n\nDuring FW-fatal recovery the disable runs while dev->state ==\nINTERNAL_ERROR. The promisc query inside esw_update_vport_rx_mode()\nfails and returns early, leaving vport->allmulti_rule intact, so\nesw_update_vport_mc_promisc() runs and adds MLX5_ACTION_ADD entries\nto vport->mc_list whose flow rules are then installed in the FDB\nby esw_add_mc_addr(). esw_destroy_legacy_table() tears down the\nFDB with those refs still held, corrupting the sub-tree and\nleaving dangling flow_rule pointers in vport->mc_list.\n\nTwo-stage failure on `echo 1 > /sys/bus/pci/devices/<bdf>/reset`:\n\n  refcount_t: underflow; use-after-free.\n   tree_put_node+0xef/0x110 [mlx5_core]\n   clean_tree+0x44/0xd0 [mlx5_core] (x5)\n   mlx5_fs_core_cleanup+0x57/0x1c0 [mlx5_core]\n   mlx5_unload+0x65/0xd0 [mlx5_core]\n   ... mlx5_health_try_recover\n\n  BUG: unable to handle page fault for address: 0000000003000055\n   down_write+0x1c/0x60\n   mlx5_del_flow_rules+0x33/0x1f0 [mlx5_core]\n   esw_del_mc_addr+0x7b/0x170 [mlx5_core]\n   esw_apply_vport_addr_list+0x56/0xf0 [mlx5_core]\n   esw_vport_change_handle_locked+0x28b/0x310 [mlx5_core]\n   mlx5_esw_vport_enable+0x270/0x4a0 [mlx5_core]\n   ... mlx5_load ... mlx5_health_try_recover\n\nesw_apply_vport_rx_mode(false, false) clears vport->allmulti_rule\nvia its local state machine even when the FW del fails. With the\nrule NULL the !IS_ERR_OR_NULL(allmulti_rule) gate in the change\nhandler closes, no rules are installed during disable, and the\nreload starts with a clean mc_list.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}