PT-2026-106613 · Linux · Linux

CVE-2026-98284

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
netlink: do not free nlk->groups while lockless readers can use it
netlink realloc groups() uses krealloc() under netlink table grab(). Whenever NLGRPSZ(groups) lands in a different kmalloc bucket, the old bitmap is freed immediately.
Two readers of nlk->groups / nlk->ngroups do not hold the netlink table lock:
  1. sk diag dump groups(). Hashed (bound) sockets are dumped from the rhashtable walk in netlink diag dump(), which only holds RCU. Only the mc list part of the dump takes nl table lock.
  2. netlink native seq show() (/proc/net/netlink), whose walk has been lockless since commit 21e4902aea80 ("netlink: Lockless lookup with RCU grace period in socket release").
Both can read a freed buffer, and sk diag dump groups() can also read past the end of the old (smaller) buffer if it happens to load the old @groups pointer together with the new @ngroups value, copying the result into a NETLINK DIAG GROUPS attribute.
This is the same class of bug that commit f773608026ee ("netlink: access nlk groups safely in netlink bind and getname") fixed for bind() and getname(); these two readers were missed. Simply grabbing the table lock in sk diag dump groups() is not an option, because it is also called with nl table lock already held from the mc list section of the dump.
Make the lockless readers safe instead:
  • Allocate a new bitmap and free the old one after an RCU grace period, instead of relying on the implicit kfree() done by krealloc().
  • Publish @groups before @ngroups, both with release semantics, and have the lockless readers load @ngroups first. A reader can then never pair the new (bigger) size with the old (smaller) buffer, and a reader picking up the new pointer while still seeing the old size is guaranteed to see the initialized bitmap.
netlink realloc groups() is called from process context (bind() and setsockopt()), so kfree rcu mightsleep() can be used, once the table has been released.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98284

Produtos afetados

Linux