PT-2026-98763 · Linux · Linux

CVE-2026-98101

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ipv6: mcast: use copy-on-write RCU updates in ip6 mc source()
pmc->sflist is read locklessly under rcu read lock() by inet6 mc check() during packet reception in the UDP and RAW multicast receive paths.
ip6 mc source() mutated psl->sl addr and psl->sl count in-place when adding or removing a source filter. Additionally, when expanding the filter buffer, newpsl was published via rcu assign pointer() before writing the new source into the array.
Because 16-byte struct in6 addr writes are not atomic and array shifting is not synchronized with RCU readers, concurrent readers in inet6 mc check() could read torn IPv6 addresses or observe duplicated/missed source entries.
Fix this by switching ip6 mc source() to copy-on-write RCU updates: allocate and fully populate newpsl before publishing it via rcu assign pointer(), and reclaim the old filter via kfree rcu(), matching ip6 mc msfilter().
Also remove the now unused IP6 SFBLOCK macro.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98101

Affected Products

Linux