PT-2026-106676 · Linux · Linux
CVE-2026-98347
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
IB/IPoIB: Avoid restoring OPER UP after multicast flush
ipoib ib dev flush light() temporarily clears IPOIB FLAG OPER UP to
prevent multicast joins while ipoib mcast dev flush() is running, and
restores the flag afterwards if it was previously set.
This restore races with ipoib ib dev down(). If the interface is brought
down while the flush is in progress, ipoib ib dev down() clears
IPOIB FLAG OPER UP, but the flush path may set it again after the device
has already gone down.
Since commit 894021a75291 ("IB/ipoib: Make the carrier on task race
aware"), ipoib mcast carrier on task() relies on IPOIB FLAG OPER UP
being cleared to terminate its rtnl trylock() retry loop. If the flag is
left set after shutdown, the workqueue retries forever, causing teardown
to deadlock when ipoib ndo uninit() waits in destroy workqueue() while
holding RTNL.
Instead of overloading IPOIB FLAG OPER UP to block multicast joins
during a light flush, introduce a dedicated IPOIB FLAG MCAST FLUSH flag.
Use it together with IPOIB FLAG OPER UP to determine whether multicast
joins are allowed, avoiding the race with device shutdown.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux