CVE-2026-98028 PUBLISHED

eth: nfp: drop the replaced rule from the list when reprogramming fails

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

eth: nfp: drop the replaced rule from the list when reprogramming fails

nfp_net_fs_add() replaces an existing rule by deleting it from the hardware, decrementing nn->fs.count and programming the new one. If nfp_net_fs_add_hw() fails the old entry stays on nn->fs.list - only the success path reaches list_replace() - so the list is one longer than nn->fs.count, and it advertises a rule whose hardware entry has already been torn down.

nn->fs.count is what ETHTOOL_GRXCLSRLCNT reports, so userspace then sizes its buffer one entry short of what the GRXCLSRLALL walk wants to write. That used to overwrite one u32 past the allocation; since the walk is bounded it is a permanent -EMSGSIZE instead, as nothing ever resyncs the counter.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 9eb03bb1c035ff6e2c3a34046419446588253dda to 603b70093f729f52a37544b48679903cad834856 (excl.)
  • affected from 9eb03bb1c035ff6e2c3a34046419446588253dda to edaec279f59f801a05b751df475ed71a0a68c88a (excl.)
  • affected from 9eb03bb1c035ff6e2c3a34046419446588253dda to 552e528a7d85cbe088b2ae4f78194713975b46cf (excl.)
  • affected from 9eb03bb1c035ff6e2c3a34046419446588253dda to 108bb2142e3a12c9ad625ad662973127a113ddc6 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.8 is affected
  • unaffected from 0 to 6.8 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc3 to * (incl.)

References