CVE-2026-98016 PUBLISHED

net/mlx5e: Fix use-after-free race in sample_restore_put()

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: Fix use-after-free race in sample_restore_put()

Concurrent teardown of TC sample rules sharing the same restore context may re-read restore->count after dropping restore_lock. At that point another thread may already have completed cleanup and freed the restore object.

Use the result of the refcount decrement while holding restore_lock to determine whether cleanup is needed.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 36a3196256bf3310e5e7142b0e61787f7a201abd to 3efd1a1938cbb33c53b0d75e55b6c0fe2ebad79a (excl.)
  • affected from 36a3196256bf3310e5e7142b0e61787f7a201abd to 72324da8eeca269db9196c2a555abf72eb0385c5 (excl.)
  • affected from 36a3196256bf3310e5e7142b0e61787f7a201abd to 1daecd76ab9e5f055fe3970462410ad1d40bd177 (excl.)
  • affected from 36a3196256bf3310e5e7142b0e61787f7a201abd to af3aef0245abbab5e9f6302e7a7d6407187afb71 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.13 is affected
  • unaffected from 0 to 5.13 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc3 to * (incl.)

References