PT-2026-106613 · Linux · Linux
CVE-2026-98284
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
netlink: do not free nlk->groups while lockless readers can use it
netlink realloc groups() uses krealloc() under netlink table grab().
Whenever NLGRPSZ(groups) lands in a different kmalloc bucket, the old
bitmap is freed immediately.
Two readers of nlk->groups / nlk->ngroups do not hold the netlink
table lock:
-
sk diag dump groups(). Hashed (bound) sockets are dumped from the rhashtable walk in netlink diag dump(), which only holds RCU. Only the mc list part of the dump takes nl table lock.
-
netlink native seq show() (/proc/net/netlink), whose walk has been lockless since commit 21e4902aea80 ("netlink: Lockless lookup with RCU grace period in socket release").
Both can read a freed buffer, and sk diag dump groups() can also read
past the end of the old (smaller) buffer if it happens to load the old
@groups pointer together with the new @ngroups value, copying the
result into a NETLINK DIAG GROUPS attribute.
This is the same class of bug that commit f773608026ee ("netlink:
access nlk groups safely in netlink bind and getname") fixed for bind()
and getname(); these two readers were missed. Simply grabbing the table
lock in sk diag dump groups() is not an option, because it is also
called with nl table lock already held from the mc list section of the
dump.
Make the lockless readers safe instead:
-
Allocate a new bitmap and free the old one after an RCU grace period, instead of relying on the implicit kfree() done by krealloc().
-
Publish @groups before @ngroups, both with release semantics, and have the lockless readers load @ngroups first. A reader can then never pair the new (bigger) size with the old (smaller) buffer, and a reader picking up the new pointer while still seeing the old size is guaranteed to see the initialized bitmap.
netlink realloc groups() is called from process context (bind() and
setsockopt()), so kfree rcu mightsleep() can be used, once the table
has been released.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux