PT-2026-98762 · Linux · Linux
CVE-2026-98099
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ipv6: mcast: use rcu assign pointer() for rcu list updates
Several places in net/ipv6/mcast.c update RCU-protected lists
(np->ipv6 mc list, idev->mc list, idev->mc tomb) using direct pointer
assignments instead of rcu assign pointer():
- In ipv6 dev mc dec(), unlinking a group from idev->mc list did: *map = ma->next; without rcu assign pointer() while concurrent readers traverse idev->mc list locklessly under rcu read lock().
- In ipv6 sock mc drop() and ipv6 sock mc close(), unlinking a group from np->ipv6 mc list directly assigned *lnk = mc lst->next and np->ipv6 mc list = mc lst->next without rcu assign pointer(), racing with lockless readers in inet6 mc check().
- In ipv6 sock mc join(), mc lst->next was initialized to np->ipv6 mc list via raw assignment before publishing mc lst.
- In mld del delrec() and ipv6 dev mc inc(), rcu source pointers passed into rcu assign pointer() lacked explicit dereference helpers.
Fix these by consistently using rcu assign pointer() along with
mc dereference() / sock dereference().
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux