« Volver al listado

CVE-2026-98102

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src()

When removing a source filter whose count reaches zero, ip6_mc_del1_src() unlinks psf from pmc->mca_sources. If the filter was previously active, the code moved psf directly into pmc->mca_tomb by updating psf->sf_next.

Because pmc->mca_sources is traversed locklessly under RCU (e.g. by ipv6_chk_mcast_addr()), mutating psf->sf_next before a grace period elapses diverts concurrent readers to the tombstone list. Consequently, readers miss remaining active sources in pmc->mca_sources and improperly examine deleted tombstone entries.

Leer descripción completaMostrar menos

Fix this by allocating a new tombstone node for pmc->mca_tomb (as done in sf_setstate()) and retiring the original psf via kfree_rcu().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98102",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4b200e398953c237c86d32bf26d4cb2a96556a6f",
              "lessThan": "c3343cd7ec8706c221e52b782f386b9af14a928a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4b200e398953c237c86d32bf26d4cb2a96556a6f",
              "lessThan": "4352737297b262e8367675c19a7dc6a9f53c97af",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4b200e398953c237c86d32bf26d4cb2a96556a6f",
              "lessThan": "8d4fe5c13f5056faa6deb09a90e24a89f9ebfad4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4b200e398953c237c86d32bf26d4cb2a96556a6f",
              "lessThan": "5149c60c406595b56fda0c6e9aae7fd287f636aa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4b200e398953c237c86d32bf26d4cb2a96556a6f",
              "lessThan": "93b49239840b91313adbd77b8b52993eff2d08c1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "86c49119f0353f857cc08030ec9e4ebaab3d5a64",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.261",
              "lessThan": "5.11",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/ipv6/mcast.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/ipv6/mcast.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:39.943",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4352737297b262e8367675c19a7dc6a9f53c97af",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5149c60c406595b56fda0c6e9aae7fd287f636aa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8d4fe5c13f5056faa6deb09a90e24a89f9ebfad4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/93b49239840b91313adbd77b8b52993eff2d08c1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c3343cd7ec8706c221e52b782f386b9af14a928a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: fix RCU list diversion in ip6_mc_del1_src()\n\nWhen removing a source filter whose count reaches zero, ip6_mc_del1_src()\nunlinks psf from pmc->mca_sources. If the filter was previously active,\nthe code moved psf directly into pmc->mca_tomb by updating psf->sf_next.\n\nBecause pmc->mca_sources is traversed locklessly under RCU (e.g. by\nipv6_chk_mcast_addr()), mutating psf->sf_next before a grace period\nelapses diverts concurrent readers to the tombstone list. Consequently,\nreaders miss remaining active sources in pmc->mca_sources and improperly\nexamine deleted tombstone entries.\n\nFix this by allocating a new tombstone node for pmc->mca_tomb (as done\nin sf_setstate()) and retiring the original psf via kfree_rcu()."
    }
  ],
  "lastModified": "2026-10-03T11:18:32.423",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}