-

CVE-2026-98101

ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source()

In the Linux kernel, the following vulnerability has been resolved:

ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source()

pmc->sflist is read locklessly under rcu_read_lock() by
inet6_mc_check() during packet reception in the UDP and RAW
multicast receive paths.

ip6_mc_source() mutated psl->sl_addr and psl->sl_count in-place
when adding or removing a source filter. Additionally, when expanding
the filter buffer, newpsl was published via rcu_assign_pointer()
before writing the new source into the array.

Because 16-byte struct in6_addr writes are not atomic and array
shifting is not synchronized with RCU readers, concurrent readers in
inet6_mc_check() could read torn IPv6 addresses or observe
duplicated/missed source entries.

Fix this by switching ip6_mc_source() to copy-on-write RCU updates:
allocate and fully populate newpsl before publishing it via
rcu_assign_pointer(), and reclaim the old filter via kfree_rcu(),
matching ip6_mc_msfilter().

Also remove the now unused IP6_SFBLOCK macro.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 882ba1f73c06831f2a21044ebd8864c485ac04f2
Version < ac51321d3b2391860a935820ebcf4d8b9bb16a8a
Status affected
Version 882ba1f73c06831f2a21044ebd8864c485ac04f2
Version < dba00514bf668c26cb4900e9f0da84bf96bf065a
Status affected
Version 882ba1f73c06831f2a21044ebd8864c485ac04f2
Version < 2c2091e2ee93049fc513ad1e6c99d8b6c809f467
Status affected
Version 882ba1f73c06831f2a21044ebd8864c485ac04f2
Version < 20db91a052332ef5552bd2f651ffb9db911cf67b
Status affected
Version 882ba1f73c06831f2a21044ebd8864c485ac04f2
Version < c073d1b070f171d206b19c98d71739a97f15b3f1
Status affected
Version 47c75e3923c8d562fea8daf0ccf31546a7bef0ea
Status affected
Version 5.10.261
Version < 5.11
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.13
Status affected
Version 0
Version < 5.13
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2c2091e2ee93049fc513ad1e6c99d8b6c809f467
https://git.kernel.org/stable/c/20db91a052332ef5552bd2f651ffb9db911cf67b
https://git.kernel.org/stable/c/c073d1b070f171d206b19c98d71739a97f15b3f1
https://git.kernel.org/stable/c/ac51321d3b2391860a935820ebcf4d8b9bb16a8a
https://git.kernel.org/stable/c/dba00514bf668c26cb4900e9f0da84bf96bf065a