Bug 2541026 (CVE-2026-98015) - CVE-2026-98015 kernel: net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put
Summary: CVE-2026-98015 kernel: net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch...
Keywords:
Status: NEW
Alias: CVE-2026-98015
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 10:44 UTC by OSIDB Bzimport
Modified: 2026-09-28 20:14 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 10:44:28 UTC
In the Linux kernel, the following vulnerability has been resolved:

net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put

In mlx5_eswitch_termtbl_put(), the zero-ref cleanup check reads
tt->ref_count after termtbl_mutex has been released.  Two concurrent
callers on the same mlx5_termtbl_handle race: one decrements ref_count
to zero, removes the hash entry, and calls kfree(tt) while the other
has already dropped the mutex and is about to evaluate
if (!tt->ref_count), producing a use-after-free.

Fix this by capturing the result of the decrement into a stack-local
last variable before dropping the mutex.  The cleanup decision is now
made entirely under termtbl_mutex, and tt is not touched after
kfree.


Note You need to log in before you can comment on or make changes to this bug.