๐Ÿ” CVE Alert

CVE-2026-98347

UNKNOWN 0.0

IB/IPoIB: Avoid restoring OPER_UP after multicast flush

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: IB/IPoIB: Avoid restoring OPER_UP after multicast flush ipoib_ib_dev_flush_light() temporarily clears IPOIB_FLAG_OPER_UP to prevent multicast joins while ipoib_mcast_dev_flush() is running, and restores the flag afterwards if it was previously set. This restore races with ipoib_ib_dev_down(). If the interface is brought down while the flush is in progress, ipoib_ib_dev_down() clears IPOIB_FLAG_OPER_UP, but the flush path may set it again after the device has already gone down. Since commit 894021a75291 ("IB/ipoib: Make the carrier_on_task race aware"), ipoib_mcast_carrier_on_task() relies on IPOIB_FLAG_OPER_UP being cleared to terminate its rtnl_trylock() retry loop. If the flag is left set after shutdown, the workqueue retries forever, causing teardown to deadlock when ipoib_ndo_uninit() waits in destroy_workqueue() while holding RTNL. Instead of overloading IPOIB_FLAG_OPER_UP to block multicast joins during a light flush, introduce a dedicated IPOIB_FLAG_MCAST_FLUSH flag. Use it together with IPOIB_FLAG_OPER_UP to determine whether multicast joins are allowed, avoiding the race with device shutdown.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
344bacca8cd811809fc33a249f2738ab757d327f < f973769fb7cb33ba0d4a64b7dcfee0cabaead938 344bacca8cd811809fc33a249f2738ab757d327f < b72f38929f4b5aa83161fd3b22a7327207e51ec5 344bacca8cd811809fc33a249f2738ab757d327f < 1b11e4b55b41d9e69a8e8d07622614202e2eaca9 344bacca8cd811809fc33a249f2738ab757d327f < 326f7d34bd7e64de535566b65c0533b640df5a81 344bacca8cd811809fc33a249f2738ab757d327f < 5ad925d45f28464a5e043c9620880bb6a030da89 344bacca8cd811809fc33a249f2738ab757d327f < 188b334a6db36a8e0bfaaf59bc4020639a0f3aad 344bacca8cd811809fc33a249f2738ab757d327f < 1ff3add37c329704ec46181b4ae4f00f9f16ce6f 344bacca8cd811809fc33a249f2738ab757d327f < 9a141d3dc869d18b2eab35e999f4790a9b84e40f a289c65ca49d2680a3d797e633e57a45573d1df2 b81459c78935e4579a577b2366c5f8878d3c7fee 8a9d8dc9ce83a90bfbbe69181acc4cf1beff46f5 dfe809702a11bd7fb91c882fb55620e39ce22109 87160fb51bc343793cc8f5f031a87f1a35aecb82 749fd55dd210f9676f0d445a6efaaa3bec65174a 3.2.84 < 3.3 3.10.105 < 3.11 3.12.65 < 3.13 3.16.39 < 3.17 4.4.24 < 4.5 4.7.7 < 4.8
Linux / Linux
4.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f973769fb7cb33ba0d4a64b7dcfee0cabaead938 git.kernel.org: https://git.kernel.org/stable/c/b72f38929f4b5aa83161fd3b22a7327207e51ec5 git.kernel.org: https://git.kernel.org/stable/c/1b11e4b55b41d9e69a8e8d07622614202e2eaca9 git.kernel.org: https://git.kernel.org/stable/c/326f7d34bd7e64de535566b65c0533b640df5a81 git.kernel.org: https://git.kernel.org/stable/c/5ad925d45f28464a5e043c9620880bb6a030da89 git.kernel.org: https://git.kernel.org/stable/c/188b334a6db36a8e0bfaaf59bc4020639a0f3aad git.kernel.org: https://git.kernel.org/stable/c/1ff3add37c329704ec46181b4ae4f00f9f16ce6f git.kernel.org: https://git.kernel.org/stable/c/9a141d3dc869d18b2eab35e999f4790a9b84e40f