« Volver al listado

CVE-2026-97939

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ipmr: account multicast table and route memory

A netadmin in a user+net namespace can create many IPv4 and IPv6 multicast routing tables with MRT_TABLE and MRT6_TABLE. Each unseen id allocates an mr_table via the shared mr_table_alloc(), links it into the per-net list, and leaves it until netns teardown. Those objects were not charged to memcg, so the host unreclaimable slab grows with the table count.

Account mr_table allocations with GFP_KERNEL_ACCOUNT and mark the IPv4/IPv6 MFC caches SLAB_ACCOUNT. This matches the established handling of IP addresses, routes and alternate interface names.

Leer descripción completaMostrar menos

Unresolved MFC entries are still allocated from softIRQ with GFP_ATOMIC and are not charged. They expire after 10 seconds and are bounded by the socket receive queue; see commit 0079ad8e8dc3 ("ipmr: remove hard code cache_resolve_queue_len limit").

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97939",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f0ad0860d01e47a3ffd220564c5c653b3afbe962",
              "lessThan": "ec1c6140394ee87127479bc500a3158b125bf07a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f0ad0860d01e47a3ffd220564c5c653b3afbe962",
              "lessThan": "0264b3ee09b118fec8a5471b4ca288f8ab84722f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f0ad0860d01e47a3ffd220564c5c653b3afbe962",
              "lessThan": "d0a2e2a4ee6bfe51e398bfb6921a7d0f4c26bc1c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f0ad0860d01e47a3ffd220564c5c653b3afbe962",
              "lessThan": "b7ee18725f2292ab554aa96a101ae42d45f008bd",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/ipv4/ipmr.c",
            "net/ipv4/ipmr_base.c",
            "net/ipv6/ip6mr.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.35"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.35",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/ipv4/ipmr.c",
            "net/ipv4/ipmr_base.c",
            "net/ipv6/ip6mr.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:21.303",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0264b3ee09b118fec8a5471b4ca288f8ab84722f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b7ee18725f2292ab554aa96a101ae42d45f008bd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d0a2e2a4ee6bfe51e398bfb6921a7d0f4c26bc1c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ec1c6140394ee87127479bc500a3158b125bf07a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipmr: account multicast table and route memory\n\nA netadmin in a user+net namespace can create many IPv4 and IPv6\nmulticast routing tables with MRT_TABLE and MRT6_TABLE. Each unseen\nid allocates an mr_table via the shared mr_table_alloc(), links it\ninto the per-net list, and leaves it until netns teardown. Those\nobjects were not charged to memcg, so the host unreclaimable slab\ngrows with the table count.\n\nAccount mr_table allocations with GFP_KERNEL_ACCOUNT and mark the\nIPv4/IPv6 MFC caches SLAB_ACCOUNT. This matches the established\nhandling of IP addresses, routes and alternate interface names.\n\nUnresolved MFC entries are still allocated from softIRQ with\nGFP_ATOMIC and are not charged. They expire after 10 seconds and are\nbounded by the socket receive queue; see commit 0079ad8e8dc3\n(\"ipmr: remove hard code cache_resolve_queue_len limit\")."
    }
  ],
  "lastModified": "2026-10-03T11:18:19.503",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}