CVE-2026-98305
Received Received - Intake

Use-After-Free in Linux Kernel DSA MXL862XX Driver

Vulnerability report for CVE-2026-98305, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: net: dsa: mxl862xx: disable the stats poll on teardown mxl862xx_setup() arms the stats poll before mxl862xx_setup_mdio(), and nothing stops it until dsa_register_switch() has returned an error to mxl862xx_probe(). DSA frees the dsa_port list before it returns, so a poll that fires once .setup or a later step of dsa_tree_setup() has failed walks freed ports. On shutdown the user ports stay registered, and the WORK_STOPPED flag test in mxl862xx_get_stats64() is not atomic with the cancel in mxl862xx_shutdown(), so a re-arm that read the flag before it was set queues the poll after cancel_delayed_work_sync() has returned. Arm the poll once .setup has succeeded and stop it from a .teardown op, which DSA calls on unregister and after a failed registration, in both cases before it frees the ports. Use disable_delayed_work_sync() there and in shutdown(): it drains a running poll as the cancel did and turns every later attempt to queue the work into a no-op, so the re-arm cannot bring the poll back. remove() and the probe error path only set WORK_STOPPED, which crc_err_work tests before it walks the ports.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Linux Linux a21d33a5265f0b31d935a8b9b2b6faefb5185911
Linux Linux a21d33a5265f0b31d935a8b9b2b6faefb5185911
Linux Linux 7.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a race condition in the mxl862xx network driver. The stats poll is armed too early in the setup process, before critical resources are fully initialized. If setup fails, the poll can access freed memory, leading to potential crashes or undefined behavior. The fix ensures the poll is only armed after successful setup and properly stopped during teardown.

Detection Guidance

This vulnerability is specific to the Linux kernel's dsa mxl862xx driver and may not have direct detection commands. Monitor kernel logs for errors related to dsa or mxl862xx during network interface operations or shutdown sequences.

Impact Analysis

This vulnerability could cause system instability, crashes, or data corruption if exploited. It primarily affects systems using the mxl862xx network driver, potentially disrupting network operations or leading to denial-of-service conditions during driver initialization or shutdown.

Mitigation Strategies

Update the Linux kernel to a patched version where this issue is resolved. Avoid using the affected dsa mxl862xx driver until a fix is applied. Monitor vendor advisories for kernel updates addressing this CVE.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98305. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart