-

CVE-2026-97939

ipmr: account multicast table and route memory

In the Linux kernel, the following vulnerability has been resolved:

ipmr: account multicast table and route memory

A netadmin in a user+net namespace can create many IPv4 and IPv6
multicast routing tables with MRT_TABLE and MRT6_TABLE. Each unseen
id allocates an mr_table via the shared mr_table_alloc(), links it
into the per-net list, and leaves it until netns teardown. Those
objects were not charged to memcg, so the host unreclaimable slab
grows with the table count.

Account mr_table allocations with GFP_KERNEL_ACCOUNT and mark the
IPv4/IPv6 MFC caches SLAB_ACCOUNT. This matches the established
handling of IP addresses, routes and alternate interface names.

Unresolved MFC entries are still allocated from softIRQ with
GFP_ATOMIC and are not charged. They expire after 10 seconds and are
bounded by the socket receive queue; see commit 0079ad8e8dc3
("ipmr: remove hard code cache_resolve_queue_len limit").
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f0ad0860d01e47a3ffd220564c5c653b3afbe962
Version < ec1c6140394ee87127479bc500a3158b125bf07a
Status affected
Version f0ad0860d01e47a3ffd220564c5c653b3afbe962
Version < 0264b3ee09b118fec8a5471b4ca288f8ab84722f
Status affected
Version f0ad0860d01e47a3ffd220564c5c653b3afbe962
Version < d0a2e2a4ee6bfe51e398bfb6921a7d0f4c26bc1c
Status affected
Version f0ad0860d01e47a3ffd220564c5c653b3afbe962
Version < b7ee18725f2292ab554aa96a101ae42d45f008bd
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.35
Status affected
Version 0
Version < 2.6.35
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.086
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0264b3ee09b118fec8a5471b4ca288f8ab84722f
https://git.kernel.org/stable/c/d0a2e2a4ee6bfe51e398bfb6921a7d0f4c26bc1c
https://git.kernel.org/stable/c/b7ee18725f2292ab554aa96a101ae42d45f008bd
https://git.kernel.org/stable/c/ec1c6140394ee87127479bc500a3158b125bf07a