In the Linux kernel, the following vulnerability has been resolved:
net: dsa: remove redundant netdev_lock_ops() from conduit ethtool ops
DSA replaces the conduit (master) device's ethtool_ops with its own
wrappers that aggregate stats from both the conduit and DSA switch
ports. Taking the lock again inside the DSA wrappers causes a deadlock.
Stumbled upon this when booting qemu with fbnic and CONFIG_NET_DSA_LOOP=y
(which looks like some kind of testing device that auto-populates the ports
of eth0). `ethtool -i` is enough to deadlock. This means we have basically zero
coverage for DSA stuff with real ops locked devs.
Remove the redundant netdev_lock_ops()/netdev_unlock_ops() calls from
the DSA conduit ethtool wrappers.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-06-26 20:17
Updated : 2026-07-06 20:10
NVD link : CVE-2026-53323
Mitre link : CVE-2026-53323
CVE.ORG link : CVE-2026-53323
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-667
Improper Locking
