CVE-2026-98016

Summary

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: Fix use-after-free race in sample_restore_put()

Concurrent teardown of TC sample rules sharing the same restore context may re-read restore->count after dropping restore_lock. At that point another thread may already have completed cleanup and freed the restore object.

Use the result of the refcount decrement while holding restore_lock to determine whether cleanup is needed.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux36a3196256bf3310e5e7142b0e61787f7a201abd < 3efd1a1938cbb33c53b0d75e55b6c0fe2ebad79aaffected
LinuxLinux36a3196256bf3310e5e7142b0e61787f7a201abd < 72324da8eeca269db9196c2a555abf72eb0385c5affected
LinuxLinux36a3196256bf3310e5e7142b0e61787f7a201abd < 1daecd76ab9e5f055fe3970462410ad1d40bd177affected
LinuxLinux36a3196256bf3310e5e7142b0e61787f7a201abd < af3aef0245abbab5e9f6302e7a7d6407187afb71affected
LinuxLinux5.13affected
LinuxLinux0 < 5.13unaffected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2.7 <= 7.2.*unaffected
LinuxLinux7.3-rc3 <= *unaffected

Weaknesses

References