PT-2026-106634 · Linux · Linux
CVE-2026-98305
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: mxl862xx: disable the stats poll on teardown
mxl862xx setup() arms the stats poll before mxl862xx setup mdio(), and
nothing stops it until dsa register switch() has returned an error to
mxl862xx probe(). DSA frees the dsa port list before it returns, so a
poll that fires once .setup or a later step of dsa tree setup() has
failed walks freed ports. On shutdown the user ports stay registered,
and the WORK STOPPED flag test in mxl862xx get stats64() is not atomic
with the cancel in mxl862xx shutdown(), so a re-arm that read the flag
before it was set queues the poll after cancel delayed work sync() has
returned.
Arm the poll once .setup has succeeded and stop it from a .teardown op,
which DSA calls on unregister and after a failed registration, in both
cases before it frees the ports. Use disable delayed work sync() there
and in shutdown(): it drains a running poll as the cancel did and turns
every later attempt to queue the work into a no-op, so the re-arm
cannot bring the poll back. remove() and the probe error path only set
WORK STOPPED, which crc err work tests before it walks the ports.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux