PT-2026-98763 · Linux · Linux
CVE-2026-98101
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ipv6: mcast: use copy-on-write RCU updates in ip6 mc source()
pmc->sflist is read locklessly under rcu read lock() by
inet6 mc check() during packet reception in the UDP and RAW
multicast receive paths.
ip6 mc source() mutated psl->sl addr and psl->sl count in-place
when adding or removing a source filter. Additionally, when expanding
the filter buffer, newpsl was published via rcu assign pointer()
before writing the new source into the array.
Because 16-byte struct in6 addr writes are not atomic and array
shifting is not synchronized with RCU readers, concurrent readers in
inet6 mc check() could read torn IPv6 addresses or observe
duplicated/missed source entries.
Fix this by switching ip6 mc source() to copy-on-write RCU updates:
allocate and fully populate newpsl before publishing it via
rcu assign pointer(), and reclaim the old filter via kfree rcu(),
matching ip6 mc msfilter().
Also remove the now unused IP6 SFBLOCK macro.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux