Multicast Join Vulnerability in Linux Kernel Affecting InfiniBand/IPoIB
CVE-2026-98347

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98347?

A race condition exists in the Linux kernel's InfiniBand subsystem related to multicast joining during interface flush operations. The ipoib_ib_dev_flush_light() function temporarily disables the multicast capability by clearing the IPOIB_FLAG_OPER_UP flag. However, a race occurs if the interface is brought down while the flush operation is ongoing, potentially restoring the flag after the device has been shut down. Consequently, this can cause the multicast work to hang indefinitely, leading to system deadlocks. To remedy this, a dedicated IPOIB_FLAG_MCAST_FLUSH flag has been introduced to manage multicast state without conflicting with device shutdown operations.

Affected Version(s)

Linux 344bacca8cd811809fc33a249f2738ab757d327f

Linux 344bacca8cd811809fc33a249f2738ab757d327f

Linux 344bacca8cd811809fc33a249f2738ab757d327f < 1b11e4b55b41d9e69a8e8d07622614202e2eaca9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.