CVE-2026-98359: RDMA/core: Reject unregistering netdevs in ib_get_eth_speed
In the Linux kernel, the following vulnerability has been resolved:
RDMA/core: Reject unregistering netdevs in ibgetethspeed
ibdevicegetnetdev() intentionally returns a referenced netdevice even when it is unregistering, so matching and cleanup callers can still find the association. The reference keeps struct netdevice allocated, but does not guarantee that the device remains operational.
ibgetethspeed() uses the returned device operationally by invoking its ethtool callback. Although that call is made under RTNL, the function does not verify the registration state first. An asynchronous RDMA port query can therefore call into a netdev after NETDEVUNREGISTER and ndouninit have completed.
Check for NETREGREGISTERED while holding RTNL and return -ENODEV for a device which is being unregistered. Keeping RTNL across the check and the ethtool operation prevents unregister from starting between them.
Keep the speed fallback and warning under RTNL as well, so the warning can safely read netdev->name. Drop the netdev reference before releasing RTNL once all accesses to the device are complete.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Linux kernel systems using RDMA where an RDMA port query can occur asynchronously while an associated Ethernet netdev is being unregistered are exposed. The affected path is ib_get_eth_speed(), which invokes the netdev's ethtool callback.
What race condition is required to trigger it?
A netdev must begin unregistering and complete NETDEV_UNREGISTER and ndo_uninit while ib_get_eth_speed() is using the referenced netdev for an RDMA port query. Holding a netdev reference alone does not prevent this, because it preserves allocation but not operational availability.
What does the fix change?
The fix checks that the netdev is in NETREG_REGISTERED state while holding RTNL and returns -ENODEV when it is unregistering. RTNL remains held through the ethtool operation, preventing unregistration from beginning during access to the device.