PT-2026-98603 · Linux · Linux
CVE-2026-97939
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ipmr: account multicast table and route memory
A netadmin in a user+net namespace can create many IPv4 and IPv6
multicast routing tables with MRT TABLE and MRT6 TABLE. Each unseen
id allocates an mr table via the shared mr table alloc(), links it
into the per-net list, and leaves it until netns teardown. Those
objects were not charged to memcg, so the host unreclaimable slab
grows with the table count.
Account mr table allocations with GFP KERNEL ACCOUNT and mark the
IPv4/IPv6 MFC caches SLAB ACCOUNT. This matches the established
handling of IP addresses, routes and alternate interface names.
Unresolved MFC entries are still allocated from softIRQ with
GFP ATOMIC and are not charged. They expire after 10 seconds and are
bounded by the socket receive queue; see commit 0079ad8e8dc3
("ipmr: remove hard code cache resolve queue len limit").
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux