-
CVE-2026-98103
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:35:53
- Zuletzt bearbeitet 30.09.2026 14:10:59
- Erkennungen
igmp: convert struct ip_sf_list to RCU
In the Linux kernel, the following vulnerability has been resolved:
igmp: convert struct ip_sf_list to RCU
Commit 23d2b94043ca ("igmp: Add ip_mc_list lock in ip_check_mc_rcu")
added spin_lock_bh(&im->lock) to ip_check_mc_rcu() to prevent a
use-after-free while iterating im->sources during concurrent deletions.
However, ip_check_mc_rcu() is called from RCU read-side critical
sections in packet receive and route lookup fast paths (e.g.
__mkroute_output(), ip_route_input_rcu(), and __udp4_lib_rcv()).
When igmpv3_send_cr() or igmpv3_send_report() holds &pmc->lock and
calls add_grec() -> igmpv3_newpack() -> ip_route_output_ports(),
an XFRM policy matching a multicast destination triggers
xfrm_tmpl_resolve_one() -> xfrm4_get_saddr() -> __mkroute_output() ->
ip_check_mc_rcu(). This attempts to acquire &im->lock while &pmc->lock
is already held on the same CPU, triggering a lockdep recursive locking
warning / deadlock.
Fix this by converting IPv4 struct ip_sf_list to RCU, mirroring the
IPv6 implementation in net/ipv6/mcast.c:
1. Add struct rcu_head to struct ip_sf_list and annotate sf_next,
sources, and tomb as __rcu pointers.
2. Use rcu_assign_pointer() and kfree_rcu() for list updates and
deletions.
3. Remove spin_lock_bh(&im->lock) from ip_check_mc_rcu() and traverse
im->sources locklessly with for_each_psf_rcu(), reading and writing
counter fields with READ_ONCE() and WRITE_ONCE().
Note: RCU conversion of /proc/net/mcfilter will be done in a
separate patch.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
23d2b94043ca8835bd1e67749020e839f396a1c2
Version <
f5182dfad54277267a8cb0c004a9cd4cf35aeebb
Status
affected
Version
23d2b94043ca8835bd1e67749020e839f396a1c2
Version <
d3011d1f293478c730aa0870490afa145c37600e
Status
affected
Version
23d2b94043ca8835bd1e67749020e839f396a1c2
Version <
e3206419bdb04e2087d8cc6be324df8639b3fac5
Status
affected
Version
23d2b94043ca8835bd1e67749020e839f396a1c2
Version <
2987ee196c88dbde0463dc87d5fb209c684e34a2
Status
affected
Version
b24065948ae6c48c9e20891f8cfe9850f1d748be
Status
affected
Version
e9924c4204ede999b0515fd31a370a1e27f676bc
Status
affected
Version
78967749984cf3614de346c90f3e259ff8272735
Status
affected
Version
4768973dffed4d0126854514335ed4fe87bec1ab
Status
affected
Version
d84708451d9041dff8a81e3718f821f12d2eb6c5
Status
affected
Version
ddd7e8b7b84836c584a284b98ca9bd7a348a0558
Status
affected
Version
961447ff60291b91e27d5c32fa549c1411ad3b70
Status
affected
Version
d1a3c6d5925a8d00a32c5ef2d674dd9c0ce89c95
Status
affected
Version
4.4.284
Version <
4.5
Status
affected
Version
4.9.283
Version <
4.10
Status
affected
Version
4.14.247
Version <
4.15
Status
affected
Version
4.19.207
Version <
4.20
Status
affected
Version
5.4.145
Version <
5.5
Status
affected
Version
5.10.64
Version <
5.11
Status
affected
Version
5.13.16
Version <
5.14
Status
affected
Version
5.14.3
Version <
5.15
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.15
Status
affected
Version
0
Version <
5.15
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.054 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/f5182dfad54277267a8cb0c004a9cd4cf35aeebb
https://git.kernel.org/stable/c/d3011d1f293478c730aa0870490afa145c37600e
https://git.kernel.org/stable/c/e3206419bdb04e2087d8cc6be324df8639b3fac5
https://git.kernel.org/stable/c/2987ee196c88dbde0463dc87d5fb209c684e34a2