CVE-2026-72344: net/mlx5e: TC, skip peer flow cleanup when LAG seq is unavailable
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: TC, skip peer flow cleanup when LAG seq is unavailable
mlx5laggetdevseq() will return error when the peer isn't in the LAG or when no device is marked as master. Result bad memory access and kernel crash[1].
Hence, skip the peer when lookup fails.
Note: In case there are peer flows, they are cleaned before LAG cleared the master mark.
[1] RIP: 0010:mlx5etcdelfdbpeersflow+0x3d/0x350 [mlx5core] Call Trace: <TASK> mlx5etccleanfdbpeerflows+0xc1/0x130 [mlx5core] mlx5eswoffloadsunpair+0x3a/0x400 [mlx5core] mlx5eswoffloadsdevcomevent+0xee/0x360 [mlx5core] mlx5devcomsendevent+0x7a/0x140 [mlx5core] mlx5eswoffloadsdevcomcleanup+0x2f/0x90 [mlx5core] mlx5etceswcleanup+0x28/0xf0 [mlx5core] mlx5ereptccleanup+0x19/0x30 [mlx5core] mlx5ecleanupuplinkreptx+0x36/0x40 [mlx5core] mlx5ecleanupreptx+0x55/0x60 [mlx5core] mlx5edetachnetdev+0x96/0xf0 [mlx5core] mlx5enetdevchangeprofile+0x5b/0x120 [mlx5core] mlx5enetdevattachnicprofile+0x1b/0x30 [mlx5core] mlx5evportrepunload+0xdd/0x110 [mlx5core] eswoffloadsunloadrep+0x81/0xb0 [mlx5core] mlx5eswitchunregistervportreps+0x1d7/0x220 [mlx5core] mlx5erepremove+0x22/0x30 [mlx5core] devicereleasedriverinternal+0x194/0x1f0 busremovedevice+0xe8/0x1b0 devicedel+0x159/0x3c0 mlx5rescandriverslocked+0xbc/0x2d0 [mlx5core] mlx5unregisterdevice+0x54/0x80 [mlx5core] mlx5uninitone+0x73/0x130 [mlx5core] removeone+0x78/0xe0 [mlx5core] pcideviceremove+0x39/0xa0