« Volver al listado

CVE-2026-98103

Estado: Pendiente de análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

igmp: convert struct ip_sf_list to RCU

Commit 23d2b94043ca ("igmp: Add ip_mc_list lock in ip_check_mc_rcu") added spin_lock_bh(&im->lock) to ip_check_mc_rcu() to prevent a use-after-free while iterating im->sources during concurrent deletions.

However, ip_check_mc_rcu() is called from RCU read-side critical sections in packet receive and route lookup fast paths (e.g. __mkroute_output(), ip_route_input_rcu(), and __udp4_lib_rcv()).

When igmpv3_send_cr() or igmpv3_send_report() holds &pmc->lock and calls add_grec() -> igmpv3_newpack() -> ip_route_output_ports(), an XFRM policy matching a multicast destination triggers xfrm_tmpl_resolve_one() -> xfrm4_get_saddr() -> __mkroute_output() -> ip_check_mc_rcu().

Leer descripción completaMostrar menos

This attempts to acquire &im->lock while &pmc->lock is already held on the same CPU, triggering a lockdep recursive locking warning / deadlock.

Fix this by converting IPv4 struct ip_sf_list to RCU, mirroring the IPv6 implementation in net/ipv6/mcast.c:

Note: RCU conversion of /proc/net/mcfilter will be done in a separate patch.

Detalles técnicos trazas, registros y código del informe original
1. Add struct rcu_head to struct ip_sf_list and annotate sf_next,
   sources, and tomb as __rcu pointers.
2. Use rcu_assign_pointer() and kfree_rcu() for list updates and
   deletions.
3. Remove spin_lock_bh(&im->lock) from ip_check_mc_rcu() and traverse
   im->sources locklessly with for_each_psf_rcu(), reading and writing
   counter fields with READ_ONCE() and WRITE_ONCE().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98103",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "23d2b94043ca8835bd1e67749020e839f396a1c2",
              "lessThan": "f5182dfad54277267a8cb0c004a9cd4cf35aeebb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23d2b94043ca8835bd1e67749020e839f396a1c2",
              "lessThan": "d3011d1f293478c730aa0870490afa145c37600e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23d2b94043ca8835bd1e67749020e839f396a1c2",
              "lessThan": "e3206419bdb04e2087d8cc6be324df8639b3fac5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23d2b94043ca8835bd1e67749020e839f396a1c2",
              "lessThan": "2987ee196c88dbde0463dc87d5fb209c684e34a2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b24065948ae6c48c9e20891f8cfe9850f1d748be",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e9924c4204ede999b0515fd31a370a1e27f676bc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "78967749984cf3614de346c90f3e259ff8272735",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4768973dffed4d0126854514335ed4fe87bec1ab",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d84708451d9041dff8a81e3718f821f12d2eb6c5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ddd7e8b7b84836c584a284b98ca9bd7a348a0558",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "961447ff60291b91e27d5c32fa549c1411ad3b70",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d1a3c6d5925a8d00a32c5ef2d674dd9c0ce89c95",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4.4.284",
              "lessThan": "4.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.9.283",
              "lessThan": "4.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.14.247",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.19.207",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.4.145",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.10.64",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.13.16",
              "lessThan": "5.14",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.14.3",
              "lessThan": "5.15",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "include/linux/igmp.h",
            "net/ipv4/igmp.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/linux/igmp.h",
            "net/ipv4/igmp.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:40.613",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2987ee196c88dbde0463dc87d5fb209c684e34a2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d3011d1f293478c730aa0870490afa145c37600e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e3206419bdb04e2087d8cc6be324df8639b3fac5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f5182dfad54277267a8cb0c004a9cd4cf35aeebb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nigmp: convert struct ip_sf_list to RCU\n\nCommit 23d2b94043ca (\"igmp: Add ip_mc_list lock in ip_check_mc_rcu\")\nadded spin_lock_bh(&im->lock) to ip_check_mc_rcu() to prevent a\nuse-after-free while iterating im->sources during concurrent deletions.\n\nHowever, ip_check_mc_rcu() is called from RCU read-side critical\nsections in packet receive and route lookup fast paths (e.g.\n__mkroute_output(), ip_route_input_rcu(), and __udp4_lib_rcv()).\n\nWhen igmpv3_send_cr() or igmpv3_send_report() holds &pmc->lock and\ncalls add_grec() -> igmpv3_newpack() -> ip_route_output_ports(),\nan XFRM policy matching a multicast destination triggers\nxfrm_tmpl_resolve_one() -> xfrm4_get_saddr() -> __mkroute_output() ->\nip_check_mc_rcu(). This attempts to acquire &im->lock while &pmc->lock\nis already held on the same CPU, triggering a lockdep recursive locking\nwarning / deadlock.\n\nFix this by converting IPv4 struct ip_sf_list to RCU, mirroring the\nIPv6 implementation in net/ipv6/mcast.c:\n\n1. Add struct rcu_head to struct ip_sf_list and annotate sf_next,\n   sources, and tomb as __rcu pointers.\n2. Use rcu_assign_pointer() and kfree_rcu() for list updates and\n   deletions.\n3. Remove spin_lock_bh(&im->lock) from ip_check_mc_rcu() and traverse\n   im->sources locklessly with for_each_psf_rcu(), reading and writing\n   counter fields with READ_ONCE() and WRITE_ONCE().\n\nNote: RCU conversion of /proc/net/mcfilter will be done in a\nseparate patch."
    }
  ],
  "lastModified": "2026-09-30T14:10:59.253",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}