Linux Kernel Vulnerability in RDMA Device Management
CVE-2026-98359
What is CVE-2026-98359?
A vulnerability exists in the Linux kernel's management of RDMA devices, particularly with the ib_get_eth_speed function. This issue arises when a net_device that is undergoing unregistration is still referenced, allowing for potential unsafe access by asynchronously running RDMA port queries. This can occur after the device has been marked as unregistered and its resources deallocated, leading to operational issues. The solution involves implementing checks during operations to ensure the device's registration state is validated, thereby preventing operations on devices that are in the process of being unregistered.
Affected Version(s)
Linux d41861942fc55c14b6280d9568a0d0112037f065
Linux d41861942fc55c14b6280d9568a0d0112037f065 < 45c60ffc79771bad154f224a05753191cf1b37bc
Linux d41861942fc55c14b6280d9568a0d0112037f065 < 520cd057f138ed8dbe8e05f0eae3a8ed4c5d3a5e