PT-2026-98765 · Linux · Linux

CVE-2026-98103

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
igmp: convert struct ip sf list to RCU
Commit 23d2b94043ca ("igmp: Add ip mc list lock in ip check mc rcu") added spin lock bh(&im->lock) to ip check mc rcu() to prevent a use-after-free while iterating im->sources during concurrent deletions.
However, ip check mc rcu() is called from RCU read-side critical sections in packet receive and route lookup fast paths (e.g. mkroute output(), ip route input rcu(), and udp4 lib rcv()).
When igmpv3 send cr() or igmpv3 send report() holds &pmc->lock and calls add grec() -> igmpv3 newpack() -> ip route output ports(), an XFRM policy matching a multicast destination triggers xfrm tmpl resolve one() -> xfrm4 get saddr() -> mkroute output() -> ip check mc rcu(). This attempts to acquire &im->lock while &pmc->lock is already held on the same CPU, triggering a lockdep recursive locking warning / deadlock.
Fix this by converting IPv4 struct ip sf list to RCU, mirroring the IPv6 implementation in net/ipv6/mcast.c:
  1. Add struct rcu head to struct ip sf list and annotate sf next, sources, and tomb as rcu pointers.
  2. Use rcu assign pointer() and kfree rcu() for list updates and deletions.
  3. Remove spin lock bh(&im->lock) from ip check mc rcu() and traverse im->sources locklessly with for each psf rcu(), reading and writing counter fields with READ ONCE() and WRITE ONCE().
Note: RCU conversion of /proc/net/mcfilter will be done in a separate patch.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98103

Produtos afetados

Linux