CVE-2026-31546: net: bonding: fix NULL deref in bond_debug_rlb_hash_show
In the Linux kernel, the following vulnerability has been resolved:
net: bonding: fix NULL deref in bonddebugrlbhashshow
rlbclearslave intentionally keeps RLB hash-table entries on the rxhashtblusedhead list with slave set to NULL when no replacement slave is available. However, bonddebugrlbhashshow visites clientinfo->slave without checking if it's NULL.
Other used-list iterators in bondalb.c already handle this NULL-slave state safely:
- rlbupdateclient returns early on !clientinfo->slave - rlbrequpdateslaveclients, rlbclearslave, and rlbrebalance compare slave values before visiting - lbrequpdatesubnetclients continues if slave is NULL
The following NULL deref crash can be trigger in bonddebugrlbhashshow:
[ 1.289791] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 1.292058] RIP: 0010:bonddebugrlbhashshow (drivers/net/bonding/bonddebugfs.c:41) [ 1.293101] RSP: 0018:ffffc900004a7d00 EFLAGS: 00010286 [ 1.293333] RAX: 0000000000000000 RBX: ffff888102b48200 RCX: ffff888102b48204 [ 1.293631] RDX: ffff888102b48200 RSI: ffffffff839daad5 RDI: ffff888102815078 [ 1.293924] RBP: ffff888102815078 R08: ffff888102b4820e R09: 0000000000000000 [ 1.294267] R10: 0000000000000000 R11: 0000000000000000 R12: ffff888100f929c0 [ 1.294564] R13: ffff888100f92a00 R14: 0000000000000001 R15: ffffc900004a7ed8 [ 1.294864] FS: 0000000001395380(0000) GS:ffff888196e75000(0000) knlGS:0000000000000000 [ 1.295239] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1.295480] CR2: 0000000000000000 CR3: 0000000102adc004 CR4: 0000000000772ef0 [ 1.295897] Call Trace: [ 1.296134] seqreaditer (fs/seqfile.c:231) [ 1.296341] seqread (fs/seqfile.c:164) [ 1.296493] fullproxyread (fs/debugfs/file.c:378 (discriminator 1)) [ 1.296658] vfsread (fs/readwrite.c:572) [ 1.296981] ksysread (fs/readwrite.c:717) [ 1.297132] dosyscall64 (arch/x86/entry/syscall64.c:63 (discriminator 1) arch/x86/entry/syscall64.c:94 (discriminator 1)) [ 1.297325] entrySYSCALL64afterhwframe (arch/x86/entry/entry64.S:130)
Add a NULL check and print "(none)" for entries with no assigned slave.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Modify bond_debug_rlb_hash_show (drivers/net/bonding/bond_debugfs.c:41) to check whether the replacement/slave pointer (client_info->slave) is NULL before visiting it; for entries with no assigned slave, print "(none)" instead of dereferencing NULL.
Linux kernel bonding debugfs (bond_debug_rlb_hash_show in drivers/net/bonding/bond_debugfs.c) Add NULL check before dereferencing client_info->slave; print "(none)" when slave is NULL = Implement NULL check and display "(none)" for entries with no assigned slave
Event History
Frequently Asked Questions
What access and conditions are required to trigger the crash?
The CVSS vector indicates local access with low privileges and no user interaction. The vulnerable debug display path dereferences a NULL slave pointer when an RLB hash-table entry remains on the used list after its slave is cleared and no replacement slave is available.
What is the expected impact if it is triggered?
The reported result is a kernel NULL-pointer dereference in bond_debug_rlb_hash_show, which can crash the kernel. The CVSS assessment identifies an availability impact only, with no confidentiality or integrity impact.
How can administrators recognize this issue in a crash report?
Affected crashes identify bond_debug_rlb_hash_show in drivers/net/bonding/bond_debugfs.c and report a kernel NULL-pointer dereference. The fault occurs while processing RLB hash-table client information whose slave pointer is NULL.