CVE-2026-98347: IB/IPoIB: Avoid restoring OPER_UP after multicast flush
In the Linux kernel, the following vulnerability has been resolved:
IB/IPoIB: Avoid restoring OPERUP after multicast flush
ipoibibdevflushlight() temporarily clears IPOIBFLAGOPERUP to prevent multicast joins while ipoibmcastdevflush() is running, and restores the flag afterwards if it was previously set.
This restore races with ipoibibdevdown(). If the interface is brought down while the flush is in progress, ipoibibdevdown() clears IPOIBFLAGOPERUP, but the flush path may set it again after the device has already gone down.
Since commit 894021a75291 ("IB/ipoib: Make the carrierontask race aware"), ipoibmcastcarrierontask() relies on IPOIBFLAGOPERUP being cleared to terminate its rtnltrylock() retry loop. If the flag is left set after shutdown, the workqueue retries forever, causing teardown to deadlock when ipoibndouninit() waits in destroyworkqueue() while holding RTNL.
Instead of overloading IPOIBFLAGOPERUP to block multicast joins during a light flush, introduce a dedicated IPOIBFLAGMCASTFLUSH flag. Use it together with IPOIBFLAGOPERUP to determine whether multicast joins are allowed, avoiding the race with device shutdown.