net/mlx5: E-Switch, prevent mc_list repopulation during vport disable
Published Sep 25, 2026
No CVSS score
EPSS 0.17%
Description
In mlx5_esw_vport_disable(), move esw_apply_vport_rx_mode() ahead of esw_vport_change_handle_locked() so vport->allmulti_rule is NULL before the change handler observes it.
During FW-fatal recovery the disable runs while dev->state == INTERNAL_ERROR. The promisc query inside esw_update_vport_rx_mode() fails and returns early, leaving vport->allmulti_rule intact, so esw_update_vport_mc_promisc() runs and adds MLX5_ACTION_ADD entries to vport->mc_list whose flow rules are then installed in the FDB by esw_add_mc_addr(). esw_destroy_legacy_table() tears down the FDB with those refs still held, corrupting the sub-tree and leaving dangling flow_rule pointers in vport->mc_list.
Two-stage failure on `echo 1 > /sys/bus/pci/devices/<bdf>/reset`:
refcount_t: underflow; use-after-free. tree_put_node+0xef/0x110 [mlx5_core] clean_tree+0x44/0xd0 [mlx5_core] (x5) mlx5_fs_core_cleanup+0x57/0x1c0 [mlx5_core] mlx5_unload+0x65/0xd0 [mlx5_core] ... mlx5_health_try_recover
BUG: unable to handle page fault for address: 0000000003000055 down_write+0x1c/0x60 mlx5_del_flow_rules+0x33/0x1f0 [mlx5_core] esw_del_mc_addr+0x7b/0x170 [mlx5_core] esw_apply_vport_addr_list+0x56/0xf0 [mlx5_core] esw_vport_change_handle_locked+0x28b/0x310 [mlx5_core] mlx5_esw_vport_enable+0x270/0x4a0 [mlx5_core] ... mlx5_load ... mlx5_health_try_recover
esw_apply_vport_rx_mode(false, false) clears vport->allmulti_rule via its local state machine even when the FW del fails. With the rule NULL the !IS_ERR_OR_NULL(allmulti_rule) gate in the change handler closes, no rules are installed during disable, and the reload starts with a clean mc_list.
Affected products
-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.10.177StatusaffectedConstraints<5.11
- Version 5.15.105StatusaffectedConstraints<5.15.222
- Version 6.1.22StatusaffectedConstraints<6.1.189
- Version 6.2.9StatusaffectedConstraints<6.3
- Version
-
- Version 6.3StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.3
- Version 5.15.222StatusunaffectedConstraints<=5.15.*
- Version 6.1.189StatusunaffectedConstraints<=6.1.*
- Version 6.12.111StatusunaffectedConstraints<=6.12.*
- Version 6.18.53StatusunaffectedConstraints<=6.18.*
- Version 6.6.158StatusunaffectedConstraints<=6.6.*
- Version 7.2.7StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc3StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (7)
- https://git.kernel.org/stable/c/2196f9d3358b00fcb28835a5fde14071f51ecb96
- https://git.kernel.org/stable/c/413e04adcc1fd263cf02b1b83b4a0dbdc66bcee9
- https://git.kernel.org/stable/c/5a2b87dfceccf9065157a14a599d395c2b6281b8
- https://git.kernel.org/stable/c/668e050429c7ca688cf4e7112f97f0cd269d446b
- https://git.kernel.org/stable/c/69904608e25e8ba58111aadd9210892cf3876201
- https://git.kernel.org/stable/c/72cfcb79026cffb6490f5044153a841d360b0cfc
- https://git.kernel.org/stable/c/c0c6f4ba8a37688f7b4d4044898d88f0450d44c2
Change history (0)
No recorded changes yet.