PT-2026-98737 · Linux · Linux

CVE-2026-98074

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bonding: do not clear curr active slave prematurely when releasing all slaves
When releasing all slaves during bond destruction (all == true), bond release one() unconditionally clears bond->curr active slave to NULL in every iteration.
If a backup slave is released before the active slave, bond alb deinit slave() triggers rlb teach disabled mac on primary(), which increments the active slave dev promiscuity counter and sets bond info->primary is promisc = 1.
Because bond->curr active slave was prematurely cleared to NULL when releasing the backup slave, the subsequent iteration releasing the active slave evaluates oldcurrent as NULL, so bond change active slave(bond, NULL) is skipped. Consequently, bond alb handle active change() is never called to decrement the promiscuity counter, permanently leaking promiscuous mode on the physical device after bond teardown.
When oldcurrent == slave, bond change active slave(bond, NULL) already sets bond->curr active slave to NULL. We only need to avoid selecting a new active slave when all == true. Replace the if (all) branch with if (!all && oldcurrent == slave).
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98074

Affected Products

Linux