CVE-2026-98016
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix use-after-free race in sample_restore_put()
Concurrent teardown of TC sample rules sharing the same restore context may re-read restore->count after dropping restore_lock. At that point another thread may already have completed cleanup and freed the restore object.
Use the result of the refcount decrement while holding restore_lock to determine whether cleanup is needed.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 36a3196256bf3310e5e7142b0e61787f7a201abd < 3efd1a1938cbb33c53b0d75e55b6c0fe2ebad79a | affected |
| Linux | Linux | 36a3196256bf3310e5e7142b0e61787f7a201abd < 72324da8eeca269db9196c2a555abf72eb0385c5 | affected |
| Linux | Linux | 36a3196256bf3310e5e7142b0e61787f7a201abd < 1daecd76ab9e5f055fe3970462410ad1d40bd177 | affected |
| Linux | Linux | 36a3196256bf3310e5e7142b0e61787f7a201abd < af3aef0245abbab5e9f6302e7a7d6407187afb71 | affected |
| Linux | Linux | 5.13 | affected |
| Linux | Linux | 0 < 5.13 | unaffected |
| Linux | Linux | 6.12.111 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc3 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/3efd1a1938cbb33c53b0d75e55b6c0fe2ebad79a
- https://git.kernel.org/stable/c/72324da8eeca269db9196c2a555abf72eb0385c5
- https://git.kernel.org/stable/c/1daecd76ab9e5f055fe3970462410ad1d40bd177
- https://git.kernel.org/stable/c/af3aef0245abbab5e9f6302e7a7d6407187afb71
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.