{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98359","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.344Z","datePublished":"2026-10-06T08:46:45.938Z","dateUpdated":"2026-10-07T06:50:13.845Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:13.845Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Reject unregistering netdevs in ib_get_eth_speed\n\nib_device_get_netdev() intentionally returns a referenced net_device even\nwhen it is unregistering, so matching and cleanup callers can still find\nthe association. The reference keeps struct net_device allocated, but does\nnot guarantee that the device remains operational.\n\nib_get_eth_speed() uses the returned device operationally by invoking its\nethtool callback. Although that call is made under RTNL, the function does\nnot verify the registration state first. An asynchronous RDMA port query\ncan therefore call into a netdev after NETDEV_UNREGISTER and ndo_uninit\nhave completed.\n\nCheck for NETREG_REGISTERED while holding RTNL and return -ENODEV for a\ndevice which is being unregistered. Keeping RTNL across the check and the\nethtool operation prevents unregister from starting between them.\n\nKeep the speed fallback and warning under RTNL as well, so the warning can\nsafely read netdev->name. Drop the netdev reference before releasing RTNL\nonce all accesses to the device are complete."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - ib_get_eth_speed() is reached via ib_query_port() -> driver query_port (rxe_query_port, siw_query_port, irdma, bnxt_re, hns, mana, erdma...) from local uverbs QUERY_PORT ioctls on /dev/infiniband/uverbs*, RDMA_NLDEV_CMD_PORT_GET netlink or the ib cache work; no remote peer supplies data to this path.\nAC:H - The faulty call needs the port's bound netdev to be between NETDEV_UNREGISTER/ndo_uninit and the queued ib_unregister_device_queued() teardown. The querying user can hammer query_port, but unregistering that netdev is an admin or driver action they cannot arrange on demand.\nPR:L - The query side needs no capability: RDMA_NLDEV_CMD_PORT_GET has no RDMA_NL_ADMIN_PERM flag, and uverbs query_port only needs an open uverbs device. Binding rxe/siw via RDMA_NLDEV_CMD_NEWLINK needs init-ns CAP_NET_ADMIN, so the attacker relies on an existing RoCE/iWARP port.\nUI:N - No victim action is needed. The attacker only issues port queries, and the unregister event is a system state change (counted under AC:H), not a user being tricked into doing something.\nS:U - The bug and its impact are both in the host kernel. No VM, IOMMU or sandbox boundary is crossed.\nC:H - __ethtool_get_link_ksettings() runs on a netdev whose ndo_uninit has already run. For example, ipvlan_ethtool_get_link_ksettings() dereferences ipvlan->phy_dev after ipvlan_port_put() dropped the port's phy_dev reference, which lets freed net_device memory be read.\nI:H - The stale or freed lower net_device is used to load and call ethtool_ops->get_link_ksettings through a function pointer. A use-after-free that reaches an indirect call can be groomed toward control-flow hijack.\nA:H - syzbot hit this as a kernel crash. Calling ethtool callbacks on a torn-down device (freed pcpu/port state in macvlan/ipvlan/team uninit) oopses the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/verbs.c"],"versions":[{"version":"d41861942fc55c14b6280d9568a0d0112037f065","lessThan":"be4b44c8b47c67a04c08b1a0aba18006b749ae6a","status":"affected","versionType":"git"},{"version":"d41861942fc55c14b6280d9568a0d0112037f065","lessThan":"45c60ffc79771bad154f224a05753191cf1b37bc","status":"affected","versionType":"git"},{"version":"d41861942fc55c14b6280d9568a0d0112037f065","lessThan":"520cd057f138ed8dbe8e05f0eae3a8ed4c5d3a5e","status":"affected","versionType":"git"},{"version":"d41861942fc55c14b6280d9568a0d0112037f065","lessThan":"a219459fbd1b2598e63c81a52847eba6c28b72d2","status":"affected","versionType":"git"},{"version":"d41861942fc55c14b6280d9568a0d0112037f065","lessThan":"5bd42f74ec3b4f4687fb600f367af0828d513b3c","status":"affected","versionType":"git"},{"version":"d41861942fc55c14b6280d9568a0d0112037f065","lessThan":"ef9fbe1b93f3b617b96e86d5cd76b3fa44514cb5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/verbs.c"],"versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/be4b44c8b47c67a04c08b1a0aba18006b749ae6a"},{"url":"https://git.kernel.org/stable/c/45c60ffc79771bad154f224a05753191cf1b37bc"},{"url":"https://git.kernel.org/stable/c/520cd057f138ed8dbe8e05f0eae3a8ed4c5d3a5e"},{"url":"https://git.kernel.org/stable/c/a219459fbd1b2598e63c81a52847eba6c28b72d2"},{"url":"https://git.kernel.org/stable/c/5bd42f74ec3b4f4687fb600f367af0828d513b3c"},{"url":"https://git.kernel.org/stable/c/ef9fbe1b93f3b617b96e86d5cd76b3fa44514cb5"}],"title":"RDMA/core: Reject unregistering netdevs in ib_get_eth_speed","x_generator":{"engine":"bippy-1.2.0"}}}}