« Volver al listado

CVE-2026-98101

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source()

pmc->sflist is read locklessly under rcu_read_lock() by inet6_mc_check() during packet reception in the UDP and RAW multicast receive paths.

ip6_mc_source() mutated psl->sl_addr and psl->sl_count in-place when adding or removing a source filter. Additionally, when expanding the filter buffer, newpsl was published via rcu_assign_pointer() before writing the new source into the array.

Because 16-byte struct in6_addr writes are not atomic and array shifting is not synchronized with RCU readers, concurrent readers in inet6_mc_check() could read torn IPv6 addresses or observe duplicated/missed source entries.

Leer descripción completaMostrar menos

Fix this by switching ip6_mc_source() to copy-on-write RCU updates: allocate and fully populate newpsl before publishing it via rcu_assign_pointer(), and reclaim the old filter via kfree_rcu(), matching ip6_mc_msfilter().

Also remove the now unused IP6_SFBLOCK macro.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98101",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "882ba1f73c06831f2a21044ebd8864c485ac04f2",
              "lessThan": "ac51321d3b2391860a935820ebcf4d8b9bb16a8a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "882ba1f73c06831f2a21044ebd8864c485ac04f2",
              "lessThan": "dba00514bf668c26cb4900e9f0da84bf96bf065a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "882ba1f73c06831f2a21044ebd8864c485ac04f2",
              "lessThan": "2c2091e2ee93049fc513ad1e6c99d8b6c809f467",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "882ba1f73c06831f2a21044ebd8864c485ac04f2",
              "lessThan": "20db91a052332ef5552bd2f651ffb9db911cf67b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "882ba1f73c06831f2a21044ebd8864c485ac04f2",
              "lessThan": "c073d1b070f171d206b19c98d71739a97f15b3f1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "47c75e3923c8d562fea8daf0ccf31546a7bef0ea",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.261",
              "lessThan": "5.11",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "include/net/if_inet6.h",
            "net/ipv6/mcast.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/net/if_inet6.h",
            "net/ipv6/mcast.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:39.830",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/20db91a052332ef5552bd2f651ffb9db911cf67b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2c2091e2ee93049fc513ad1e6c99d8b6c809f467",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ac51321d3b2391860a935820ebcf4d8b9bb16a8a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c073d1b070f171d206b19c98d71739a97f15b3f1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dba00514bf668c26cb4900e9f0da84bf96bf065a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: use copy-on-write RCU updates in ip6_mc_source()\n\npmc->sflist is read locklessly under rcu_read_lock() by\ninet6_mc_check() during packet reception in the UDP and RAW\nmulticast receive paths.\n\nip6_mc_source() mutated psl->sl_addr and psl->sl_count in-place\nwhen adding or removing a source filter. Additionally, when expanding\nthe filter buffer, newpsl was published via rcu_assign_pointer()\nbefore writing the new source into the array.\n\nBecause 16-byte struct in6_addr writes are not atomic and array\nshifting is not synchronized with RCU readers, concurrent readers in\ninet6_mc_check() could read torn IPv6 addresses or observe\nduplicated/missed source entries.\n\nFix this by switching ip6_mc_source() to copy-on-write RCU updates:\nallocate and fully populate newpsl before publishing it via\nrcu_assign_pointer(), and reclaim the old filter via kfree_rcu(),\nmatching ip6_mc_msfilter().\n\nAlso remove the now unused IP6_SFBLOCK macro."
    }
  ],
  "lastModified": "2026-10-03T11:18:32.250",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}