CVE-2026-98016

Source
https://cve.org/CVERecord?id=CVE-2026-98016
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98016.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98016
Downstream
Published
2026-09-25T10:23:38Z
Modified
2026-09-26T03:48:31Z
Summary
net/mlx5e: Fix use-after-free race in sample_restore_put()
Details

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: Fix use-after-free race in sample_restore_put()

Concurrent teardown of TC sample rules sharing the same restore context may re-read restore->count after dropping restore_lock. At that point another thread may already have completed cleanup and freed the restore object.

Use the result of the refcount decrement while holding restore_lock to determine whether cleanup is needed.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98016.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
36a3196256bf3310e5e7142b0e61787f7a201abd
Fixed
3efd1a1938cbb33c53b0d75e55b6c0fe2ebad79a
Fixed
72324da8eeca269db9196c2a555abf72eb0385c5
Fixed
1daecd76ab9e5f055fe3970462410ad1d40bd177
Fixed
af3aef0245abbab5e9f6302e7a7d6407187afb71

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98016.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98016.json"