PT-2026-98737 · Linux · Linux
CVE-2026-98074
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bonding: do not clear curr active slave prematurely when releasing all slaves
When releasing all slaves during bond destruction (all == true),
bond release one() unconditionally clears bond->curr active slave to
NULL in every iteration.
If a backup slave is released before the active slave,
bond alb deinit slave() triggers rlb teach disabled mac on primary(),
which increments the active slave dev promiscuity counter and sets
bond info->primary is promisc = 1.
Because bond->curr active slave was prematurely cleared to NULL when
releasing the backup slave, the subsequent iteration releasing the active
slave evaluates oldcurrent as NULL, so bond change active slave(bond, NULL)
is skipped. Consequently, bond alb handle active change() is never called
to decrement the promiscuity counter, permanently leaking promiscuous
mode on the physical device after bond teardown.
When oldcurrent == slave, bond change active slave(bond, NULL) already sets
bond->curr active slave to NULL. We only need to avoid selecting a new
active slave when all == true. Replace the if (all) branch with
if (!all && oldcurrent == slave).
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux