PT-2026-106676 · Linux · Linux

CVE-2026-98347

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
IB/IPoIB: Avoid restoring OPER UP after multicast flush
ipoib ib dev flush light() temporarily clears IPOIB FLAG OPER UP to prevent multicast joins while ipoib mcast dev flush() is running, and restores the flag afterwards if it was previously set.
This restore races with ipoib ib dev down(). If the interface is brought down while the flush is in progress, ipoib ib dev down() clears IPOIB FLAG OPER UP, but the flush path may set it again after the device has already gone down.
Since commit 894021a75291 ("IB/ipoib: Make the carrier on task race aware"), ipoib mcast carrier on task() relies on IPOIB FLAG OPER UP being cleared to terminate its rtnl trylock() retry loop. If the flag is left set after shutdown, the workqueue retries forever, causing teardown to deadlock when ipoib ndo uninit() waits in destroy workqueue() while holding RTNL.
Instead of overloading IPOIB FLAG OPER UP to block multicast joins during a light flush, introduce a dedicated IPOIB FLAG MCAST FLUSH flag. Use it together with IPOIB FLAG OPER UP to determine whether multicast joins are allowed, avoiding the race with device shutdown.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98347

Affected Products

Linux