PT-2026-98737 · Linux · Linux
CVE-2026-98074
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
bonding: do not clear curr active slave prematurely when releasing all slaves
When releasing all slaves during bond destruction (all == true),
bond release one() unconditionally clears bond->curr active slave to
NULL in every iteration.
If a backup slave is released before the active slave,
bond alb deinit slave() triggers rlb teach disabled mac on primary(),
which increments the active slave dev promiscuity counter and sets
bond info->primary is promisc = 1.
Because bond->curr active slave was prematurely cleared to NULL when
releasing the backup slave, the subsequent iteration releasing the active
slave evaluates oldcurrent as NULL, so bond change active slave(bond, NULL)
is skipped. Consequently, bond alb handle active change() is never called
to decrement the promiscuity counter, permanently leaking promiscuous
mode on the physical device after bond teardown.
When oldcurrent == slave, bond change active slave(bond, NULL) already sets
bond->curr active slave to NULL. We only need to avoid selecting a new
active slave when all == true. Replace the if (all) branch with
if (!all && oldcurrent == slave).
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux