CVE-2026-98301
Description
In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: move switchdev call outside rcu This is a follow-up of one of sashiko's pre-existing bug reports. br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs while holding rcu_read_lock() which invokes the blocking switchdev notifier chain and may sleep. Nonzero MSTI changes come from netlink with rtnl held. Move the switchdev call before entering the rcu section and assert that rtnl is held. The call cannot be deferred because netlink needs its error and extack. Also DSA reads the old bridge MST state during the callback and checks it. A deferred callback will be late and will see the updated state.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/18a6fe05fb6e18de29fa90d388bb34044114b3d8
- https://git.kernel.org/stable/c/6b431b63219853eef4054e2f1cb073d2ca2059b4
- https://git.kernel.org/stable/c/abf734d150c61acfdfee102169d0e5d1c482e285
- https://git.kernel.org/stable/c/b9661fd2423fc25e91e0517ecc0b6156ad83e3a8
- https://git.kernel.org/stable/c/c40ed3e884c8dc0350f26484030438ef24208ff1
- https://git.kernel.org/stable/c/d5c4ee1fa4e83a12afc051c831936cd8e006cde3
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.