{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net/mlx5: E-Switch, prevent mc_list repopulation during vport disable  In mlx5_esw_vport_disable(), move esw_apply_vport_rx_mode() ahead of esw_vport_change_handle_locked() so vport-\u003eallmulti_rule is NULL before the change handler observes it.  During FW-fatal recovery the disable runs while dev-\u003estate == INTERNAL_ERROR. The promisc query inside esw_update_vport_rx_mode() fails and returns early, leaving vport-\u003eallmulti_rule intact, so esw_update_vport_mc_promisc() runs and adds MLX5_ACTION_ADD entries to vport-\u003emc_list whose flow rules are then installed in the FDB by esw_add_mc_addr(). esw_destroy_legacy_table() tears down the FDB with those refs still held, corrupting the sub-tree and leaving dangling flow_rule pointers in vport-\u003emc_list.  Two-stage failure on `echo 1 \u003e /sys/bus/pci/devices/\u003cbdf\u003e/reset`:    refcount_t: underflow; use-after-free.    tree_put_node+0xef/0x110 [mlx5_core]    clean_tree+0x44/0xd0 [mlx5_core] (x5)    mlx5_fs_core_cleanup+0x57/0x1c0 [mlx5_core]    mlx5_unload+0x65/0xd0 [mlx5_core]    ... mlx5_health_try_recover    BUG: unable to handle page fault for address: 0000000003000055    down_write+0x1c/0x60    mlx5_del_flow_rules+0x33/0x1f0 [mlx5_core]    esw_del_mc_addr+0x7b/0x170 [mlx5_core]    esw_apply_vport_addr_list+0x56/0xf0 [mlx5_core]    esw_vport_change_handle_locked+0x28b/0x310 [mlx5_core]    mlx5_esw_vport_enable+0x270/0x4a0 [mlx5_core]    ... mlx5_load ... mlx5_health_try_recover  esw_apply_vport_rx_mode(false, false) clears vport-\u003eallmulti_rule via its local state machine even when the FW del fails. With the rule NULL the !IS_ERR_OR_NULL(allmulti_rule) gate in the change handler closes, no rules are installed during disable, and the reload starts with a clean mc_list.",
  "id": "DEBIAN-CVE-2026-98014",
  "modified": "2026-09-26T04:47:30.768024570Z",
  "published": "2026-09-25T11:17:29.767Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98014"
    }
  ],
  "upstream": [
    "CVE-2026-98014"
  ]
}