CVE-2026-98359: RDMA/core: Reject unregistering netdevs in ib_get_eth_speed

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

RDMA/core: Reject unregistering netdevs in ibgetethspeed

ibdevicegetnetdev() intentionally returns a referenced netdevice even when it is unregistering, so matching and cleanup callers can still find the association. The reference keeps struct netdevice allocated, but does not guarantee that the device remains operational.

ibgetethspeed() uses the returned device operationally by invoking its ethtool callback. Although that call is made under RTNL, the function does not verify the registration state first. An asynchronous RDMA port query can therefore call into a netdev after NETDEVUNREGISTER and ndouninit have completed.

Check for NETREGREGISTERED while holding RTNL and return -ENODEV for a device which is being unregistered. Keeping RTNL across the check and the ethtool operation prevents unregister from starting between them.

Keep the speed fallback and warning under RTNL as well, so the warning can safely read netdev->name. Drop the netdev reference before releasing RTNL once all accesses to the device are complete.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionSeverity
Data Sourced
via NVD·09:18 AM
DescriptionSeverity
Oct 7, 2026
Data Sourced
via Microsoft·08:18 AM
DescriptionSeverityWeakness
Sep 6, 58736
Event
via FIRST·08:27 PM

Frequently Asked Questions

1

Which systems are exposed to this issue?

Linux kernel systems using RDMA where an RDMA port query can occur asynchronously while an associated Ethernet netdev is being unregistered are exposed. The affected path is ib_get_eth_speed(), which invokes the netdev's ethtool callback.

2

What race condition is required to trigger it?

A netdev must begin unregistering and complete NETDEV_UNREGISTER and ndo_uninit while ib_get_eth_speed() is using the referenced netdev for an RDMA port query. Holding a netdev reference alone does not prevent this, because it preserves allocation but not operational availability.

3

What does the fix change?

The fix checks that the netdev is in NETREG_REGISTERED state while holding RTNL and returns -ENODEV when it is unregistering. RTNL remains held through the ethtool operation, preventing unregistration from beginning during access to the device.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203