-

CVE-2026-98103

igmp: convert struct ip_sf_list to RCU

In the Linux kernel, the following vulnerability has been resolved:

igmp: convert struct ip_sf_list to RCU

Commit 23d2b94043ca ("igmp: Add ip_mc_list lock in ip_check_mc_rcu")
added spin_lock_bh(&im->lock) to ip_check_mc_rcu() to prevent a
use-after-free while iterating im->sources during concurrent deletions.

However, ip_check_mc_rcu() is called from RCU read-side critical
sections in packet receive and route lookup fast paths (e.g.
__mkroute_output(), ip_route_input_rcu(), and __udp4_lib_rcv()).

When igmpv3_send_cr() or igmpv3_send_report() holds &pmc->lock and
calls add_grec() -> igmpv3_newpack() -> ip_route_output_ports(),
an XFRM policy matching a multicast destination triggers
xfrm_tmpl_resolve_one() -> xfrm4_get_saddr() -> __mkroute_output() ->
ip_check_mc_rcu(). This attempts to acquire &im->lock while &pmc->lock
is already held on the same CPU, triggering a lockdep recursive locking
warning / deadlock.

Fix this by converting IPv4 struct ip_sf_list to RCU, mirroring the
IPv6 implementation in net/ipv6/mcast.c:

1. Add struct rcu_head to struct ip_sf_list and annotate sf_next,
   sources, and tomb as __rcu pointers.
2. Use rcu_assign_pointer() and kfree_rcu() for list updates and
   deletions.
3. Remove spin_lock_bh(&im->lock) from ip_check_mc_rcu() and traverse
   im->sources locklessly with for_each_psf_rcu(), reading and writing
   counter fields with READ_ONCE() and WRITE_ONCE().

Note: RCU conversion of /proc/net/mcfilter will be done in a
separate patch.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 23d2b94043ca8835bd1e67749020e839f396a1c2
Version < f5182dfad54277267a8cb0c004a9cd4cf35aeebb
Status affected
Version 23d2b94043ca8835bd1e67749020e839f396a1c2
Version < d3011d1f293478c730aa0870490afa145c37600e
Status affected
Version 23d2b94043ca8835bd1e67749020e839f396a1c2
Version < e3206419bdb04e2087d8cc6be324df8639b3fac5
Status affected
Version 23d2b94043ca8835bd1e67749020e839f396a1c2
Version < 2987ee196c88dbde0463dc87d5fb209c684e34a2
Status affected
Version b24065948ae6c48c9e20891f8cfe9850f1d748be
Status affected
Version e9924c4204ede999b0515fd31a370a1e27f676bc
Status affected
Version 78967749984cf3614de346c90f3e259ff8272735
Status affected
Version 4768973dffed4d0126854514335ed4fe87bec1ab
Status affected
Version d84708451d9041dff8a81e3718f821f12d2eb6c5
Status affected
Version ddd7e8b7b84836c584a284b98ca9bd7a348a0558
Status affected
Version 961447ff60291b91e27d5c32fa549c1411ad3b70
Status affected
Version d1a3c6d5925a8d00a32c5ef2d674dd9c0ce89c95
Status affected
Version 4.4.284
Version < 4.5
Status affected
Version 4.9.283
Version < 4.10
Status affected
Version 4.14.247
Version < 4.15
Status affected
Version 4.19.207
Version < 4.20
Status affected
Version 5.4.145
Version < 5.5
Status affected
Version 5.10.64
Version < 5.11
Status affected
Version 5.13.16
Version < 5.14
Status affected
Version 5.14.3
Version < 5.15
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f5182dfad54277267a8cb0c004a9cd4cf35aeebb
https://git.kernel.org/stable/c/d3011d1f293478c730aa0870490afa145c37600e
https://git.kernel.org/stable/c/e3206419bdb04e2087d8cc6be324df8639b3fac5
https://git.kernel.org/stable/c/2987ee196c88dbde0463dc87d5fb209c684e34a2