PT-2026-106634 · Linux · Linux

CVE-2026-98305

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: mxl862xx: disable the stats poll on teardown
mxl862xx setup() arms the stats poll before mxl862xx setup mdio(), and nothing stops it until dsa register switch() has returned an error to mxl862xx probe(). DSA frees the dsa port list before it returns, so a poll that fires once .setup or a later step of dsa tree setup() has failed walks freed ports. On shutdown the user ports stay registered, and the WORK STOPPED flag test in mxl862xx get stats64() is not atomic with the cancel in mxl862xx shutdown(), so a re-arm that read the flag before it was set queues the poll after cancel delayed work sync() has returned.
Arm the poll once .setup has succeeded and stop it from a .teardown op, which DSA calls on unregister and after a failed registration, in both cases before it frees the ports. Use disable delayed work sync() there and in shutdown(): it drains a running poll as the cancel did and turns every later attempt to queue the work into a no-op, so the re-arm cannot bring the poll back. remove() and the probe error path only set WORK STOPPED, which crc err work tests before it walks the ports.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98305

Produtos afetados

Linux