CVE-2026-98304

Source
https://cve.org/CVERecord?id=CVE-2026-98304
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98304.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98304
Downstream
Published
2026-10-06T08:46:01Z
Modified
2026-10-07T02:47:34Z
Summary
net: bcmgenet: restore the hardware filters on open
Details

In the Linux kernel, the following vulnerability has been resolved:

net: bcmgenet: restore the hardware filters on open

bcmgenet_hfb_init() runs INIT_LIST_HEAD() on priv->rxnfc_list, which drops every rule off the list, and bcmgenet_open() calls it on each ifup. Every rule the user configured is silently lost:

ethtool -N eth0 flow-type ether dst $MAC action 0

Added rule with ID 0

ethtool -n eth0 | grep -c Filter:

1

ip link set eth0 down && ip link set eth0 up

ethtool -n eth0 | grep -c Filter:

0

Initialise the lists once at probe and restore the rules on open, as bcmgenet_resume() already does.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98304.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3e370952287c55e5fd240cb8bb41ef8acff8829d
Fixed
56db7ec462d6a2b886e299ad835109c089606969
Fixed
906140955c8debde65afe12e594e04c49a61b0d9
Fixed
23ca4ddc4fce2c233a49e9fd34d4b5b02bd7324e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98304.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.8.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98304.json"