CVE-2026-98347
Received
Received - Intake
Race Condition in Linux Kernel IPoIB Leading to Deadlock
Vulnerability report for CVE-2026-98347, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
IB/IPoIB: Avoid restoring OPER_UP after multicast flush
ipoib_ib_dev_flush_light() temporarily clears IPOIB_FLAG_OPER_UP to
prevent multicast joins while ipoib_mcast_dev_flush() is running, and
restores the flag afterwards if it was previously set.
This restore races with ipoib_ib_dev_down(). If the interface is brought
down while the flush is in progress, ipoib_ib_dev_down() clears
IPOIB_FLAG_OPER_UP, but the flush path may set it again after the device
has already gone down.
Since commit 894021a75291 ("IB/ipoib: Make the carrier_on_task race
aware"), ipoib_mcast_carrier_on_task() relies on IPOIB_FLAG_OPER_UP
being cleared to terminate its rtnl_trylock() retry loop. If the flag is
left set after shutdown, the workqueue retries forever, causing teardown
to deadlock when ipoib_ndo_uninit() waits in destroy_workqueue() while
holding RTNL.
Instead of overloading IPOIB_FLAG_OPER_UP to block multicast joins
during a light flush, introduce a dedicated IPOIB_FLAG_MCAST_FLUSH flag.
Use it together with IPOIB_FLAG_OPER_UP to determine whether multicast
joins are allowed, avoiding the race with device shutdown.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 344bacca8cd811809fc33a249f2738ab757d327f |
| Linux | Linux | 344bacca8cd811809fc33a249f2738ab757d327f |
| Linux | Linux | 344bacca8cd811809fc33a249f2738ab757d327f |
| Linux | Linux | 344bacca8cd811809fc33a249f2738ab757d327f |
| Linux | Linux | 344bacca8cd811809fc33a249f2738ab757d327f |
| Linux | Linux | 344bacca8cd811809fc33a249f2738ab757d327f |
| Linux | Linux | 344bacca8cd811809fc33a249f2738ab757d327f |
| Linux | Linux | 344bacca8cd811809fc33a249f2738ab757d327f |
| Linux | Linux | a289c65ca49d2680a3d797e633e57a45573d1df2 |
| Linux | Linux | b81459c78935e4579a577b2366c5f8878d3c7fee |
| Linux | Linux | 8a9d8dc9ce83a90bfbbe69181acc4cf1beff46f5 |
| Linux | Linux | dfe809702a11bd7fb91c882fb55620e39ce22109 |
| Linux | Linux | 87160fb51bc343793cc8f5f031a87f1a35aecb82 |
| Linux | Linux | 749fd55dd210f9676f0d445a6efaaa3bec65174a |
| Linux | Linux | 3.2.84 |
| Linux | Linux | 3.10.105 |
| Linux | Linux | 3.12.65 |
| Linux | Linux | 3.16.39 |
| Linux | Linux | 4.4.24 |
| Linux | Linux | 4.7.7 |
| Linux | Linux | 4.8 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |