Answer in brief
CVE-2026-98359 records a Unknown severity vulnerability in RDMA/core: Reject unregistering netdevs in ib_get_eth_speed. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d41861942fc55c14b6280d9568a0d0112037f065 <be4b44c8b47c67a04c08b1a0aba18006b749ae6a || >=d41861942fc55c14b6280d9568a0d0112037f065 <45c60ffc79771bad154f224a05753191cf1b37bc || >=d41861942fc55c14b6280d9568a0d0112037f065 <520cd057f138ed8dbe8e05f0eae3a8ed4c5d3a5e || >=d41861942fc55c14b6280d9568a0d0112037f065 <a219459fbd1b2598e63c81a52847eba6c28b72d2 || >=d41861942fc55c14b6280d9568a0d0112037f065 <5bd42f74ec3b4f4687fb600f367af0828d513b3c || >=d41861942fc55c14b6280d9568a0d0112037f065 <ef9fbe1b93f3b617b96e86d5cd76b3fa44514cb5 | be4b44c8b47c67a04c08b1a0aba18006b749ae6a, 45c60ffc79771bad154f224a05753191cf1b37bc, 520cd057f138ed8dbe8e05f0eae3a8ed4c5d3a5e, a219459fbd1b2598e63c81a52847eba6c28b72d2, 5bd42f74ec3b4f4687fb600f367af0828d513b3c, ef9fbe1b93f3b617b96e86d5cd76b3fa44514cb5 |
| Linux/Linuxgeneric | 4.14 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Reject unregistering netdevs in ib_get_eth_speed ib_device_get_netdev() intentionally returns a referenced net_device even when it is unregistering, so matching and cleanup callers can still find the association. The reference keeps struct net_device allocated, but does not guarantee that the device remains operational. ib_get_eth_speed() uses the returned device operationally by invoking its ethtool callback. Although that call is made under RTNL, the function does not verify the registration state first. An asynchronous RDMA port query can therefore call into a netdev after NETDEV_UNREGISTER and ndo_uninit have completed. Check for NETREG_REGISTERED while holding RTNL and return -ENODEV for a device which is being unregistered. Keeping RTNL across the check and the ethtool operation prevents unregister from starting between them. Keep the speed fallback and warning under RTNL as well, so the warning can safely read netdev->name. Drop the netdev reference before releasing RTNL once all accesses to the device are complete.
Quoted source text, attributed separately from HOL analysis.