PT-2026-98689 · Linux · Linux

CVE-2026-98026

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: mcast: properly convert mglist to rcu
Sashiko reported a bug [1] that br multicast del port group unlists the port group not using proper rcu helper that preserves the next pointer and after that immediately frees the port group without waiting for rcu grace period. The only rcu walker of mglist is br multicast list adjacent() and it turns out that function has always been buggy because mglist was never properly converted to RCU. Fix it by converting it to rcu and moving its initialization after eth addr's. Initializing p->next can use RCU INIT POINTER because we have a barrier from the hlist add head rcu call later, besides we're initializing an unpublished structure anyway.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98026

Affected Products

Linux