9.8

CVE-2026-72323

ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()

In the Linux kernel, the following vulnerability has been resolved:

ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()

A race condition exists between device teardown (inetdev_destroy) and
incoming IGMP query processing (igmp_rcv), leading to a Use-After-Free
in the IGMP timer callback.

During device destruction, inetdev_destroy() drops the primary reference
to in_device, which can drop its refcount to 0. The actual freeing of
in_device memory is deferred via RCU (using call_rcu()).

Concurrently, igmp_rcv() runs under RCU read lock and obtains the
in_device pointer. Because the memory is RCU-protected, CPU-0 can safely
dereference in_device even if its refcount has hit 0.

However, if CPU-0 calls igmp_gq_start_timer() and re-arms the timer, it
attempts to acquire a reference using in_dev_hold(). This increments the
refcount from 0 to 1, triggering a "refcount_t: addition on 0" warning.
Since the in_device memory is still scheduled to be freed after the RCU
grace period (as the free callback does not check the refcount again),
the device is freed while the timer is still armed. When the timer
expires, it accesses the freed memory, causing a kernel panic.

Fix this by using refcount_inc_not_zero() (via a new helper
in_dev_hold_safe()) to prevent acquiring a reference if the device is
already being destroyed. If the refcount is 0, we do not arm the timer.

A similar issue in IPv6 MLD is fixed in a subsequent patch.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 7265c747eec415ca3109a6a14a419f7ae433b780
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < d107b4c4f8274763b7ea5ab05d45cef78e4b81ba
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 74b301f7f197517016befb5f5dfab01f7bc64be5
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 40a1e998cb266ed4cb529a0bb4fee2b0ba732702
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 165258303357e54b75fc19b341ae2a2b7c9e3910
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 75e984fe0cb9e7fbde0c8ee838c61ce8573d3ea3
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 8d4394ffa40508e0de72f464af351f6ca6a6cdc3
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 7b19c0f81ed1fdaec6bc522569be367199a9edf3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.10.*
Version 5.10.269
Status unaffected
Version <= 5.15.*
Version 5.15.220
Status unaffected
Version <= 6.1.*
Version 6.1.187
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.479
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/40a1e998cb266ed4cb529a0bb4fee2b0ba732702
https://git.kernel.org/stable/c/165258303357e54b75fc19b341ae2a2b7c9e3910
https://git.kernel.org/stable/c/75e984fe0cb9e7fbde0c8ee838c61ce8573d3ea3
https://git.kernel.org/stable/c/8d4394ffa40508e0de72f464af351f6ca6a6cdc3
https://git.kernel.org/stable/c/7b19c0f81ed1fdaec6bc522569be367199a9edf3
https://git.kernel.org/stable/c/7265c747eec415ca3109a6a14a419f7ae433b780
https://git.kernel.org/stable/c/74b301f7f197517016befb5f5dfab01f7bc64be5
https://git.kernel.org/stable/c/d107b4c4f8274763b7ea5ab05d45cef78e4b81ba