CVE-2026-98103
In the Linux kernel, the following vulnerability has been resolved:
igmp: convert struct ip_sf_list to RCU
Commit 23d2b94043ca ("igmp: Add ip_mc_list lock in ip_check_mc_rcu") added spin_lock_bh(&im->lock) to ip_check_mc_rcu() to prevent a use-after-free while iterating im->sources during concurrent deletions.
However, ip_check_mc_rcu() is called from RCU read-side critical sections in packet receive and route lookup fast paths (e.g. __mkroute_output(), ip_route_input_rcu(), and __udp4_lib_rcv()).
When igmpv3_send_cr() or igmpv3_send_report() holds &pmc->lock and calls add_grec() -> igmpv3_newpack() -> ip_route_output_ports(), an XFRM policy matching a multicast destination triggers xfrm_tmpl_resolve_one() -> xfrm4_get_saddr() -> __mkroute_output() -> ip_check_mc_rcu().
Leer descripción completaMostrar menos
This attempts to acquire &im->lock while &pmc->lock is already held on the same CPU, triggering a lockdep recursive locking warning / deadlock.
Fix this by converting IPv4 struct ip_sf_list to RCU, mirroring the IPv6 implementation in net/ipv6/mcast.c:
Note: RCU conversion of /proc/net/mcfilter will be done in a separate patch.
Detalles técnicos trazas, registros y código del informe original
1. Add struct rcu_head to struct ip_sf_list and annotate sf_next, sources, and tomb as __rcu pointers. 2. Use rcu_assign_pointer() and kfree_rcu() for list updates and deletions. 3. Remove spin_lock_bh(&im->lock) from ip_check_mc_rcu() and traverse im->sources locklessly with for_each_psf_rcu(), reading and writing counter fields with READ_ONCE() and WRITE_ONCE().
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98103",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "23d2b94043ca8835bd1e67749020e839f396a1c2",
"lessThan": "f5182dfad54277267a8cb0c004a9cd4cf35aeebb",
"versionType": "git"
},
{
"status": "affected",
"version": "23d2b94043ca8835bd1e67749020e839f396a1c2",
"lessThan": "d3011d1f293478c730aa0870490afa145c37600e",
"versionType": "git"
},
{
"status": "affected",
"version": "23d2b94043ca8835bd1e67749020e839f396a1c2",
"lessThan": "e3206419bdb04e2087d8cc6be324df8639b3fac5",
"versionType": "git"
},
{
"status": "affected",
"version": "23d2b94043ca8835bd1e67749020e839f396a1c2",
"lessThan": "2987ee196c88dbde0463dc87d5fb209c684e34a2",
"versionType": "git"
},
{
"status": "affected",
"version": "b24065948ae6c48c9e20891f8cfe9850f1d748be",
"versionType": "git"
},
{
"status": "affected",
"version": "e9924c4204ede999b0515fd31a370a1e27f676bc",
"versionType": "git"
},
{
"status": "affected",
"version": "78967749984cf3614de346c90f3e259ff8272735",
"versionType": "git"
},
{
"status": "affected",
"version": "4768973dffed4d0126854514335ed4fe87bec1ab",
"versionType": "git"
},
{
"status": "affected",
"version": "d84708451d9041dff8a81e3718f821f12d2eb6c5",
"versionType": "git"
},
{
"status": "affected",
"version": "ddd7e8b7b84836c584a284b98ca9bd7a348a0558",
"versionType": "git"
},
{
"status": "affected",
"version": "961447ff60291b91e27d5c32fa549c1411ad3b70",
"versionType": "git"
},
{
"status": "affected",
"version": "d1a3c6d5925a8d00a32c5ef2d674dd9c0ce89c95",
"versionType": "git"
},
{
"status": "affected",
"version": "4.4.284",
"lessThan": "4.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.9.283",
"lessThan": "4.10",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.14.247",
"lessThan": "4.15",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.19.207",
"lessThan": "4.20",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.4.145",
"lessThan": "5.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.10.64",
"lessThan": "5.11",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.13.16",
"lessThan": "5.14",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.14.3",
"lessThan": "5.15",
"versionType": "semver"
}
],
"programFiles": [
"include/linux/igmp.h",
"net/ipv4/igmp.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"include/linux/igmp.h",
"net/ipv4/igmp.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:40.613",
"references": [
{
"url": "https://git.kernel.org/stable/c/2987ee196c88dbde0463dc87d5fb209c684e34a2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d3011d1f293478c730aa0870490afa145c37600e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e3206419bdb04e2087d8cc6be324df8639b3fac5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f5182dfad54277267a8cb0c004a9cd4cf35aeebb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nigmp: convert struct ip_sf_list to RCU\n\nCommit 23d2b94043ca (\"igmp: Add ip_mc_list lock in ip_check_mc_rcu\")\nadded spin_lock_bh(&im->lock) to ip_check_mc_rcu() to prevent a\nuse-after-free while iterating im->sources during concurrent deletions.\n\nHowever, ip_check_mc_rcu() is called from RCU read-side critical\nsections in packet receive and route lookup fast paths (e.g.\n__mkroute_output(), ip_route_input_rcu(), and __udp4_lib_rcv()).\n\nWhen igmpv3_send_cr() or igmpv3_send_report() holds &pmc->lock and\ncalls add_grec() -> igmpv3_newpack() -> ip_route_output_ports(),\nan XFRM policy matching a multicast destination triggers\nxfrm_tmpl_resolve_one() -> xfrm4_get_saddr() -> __mkroute_output() ->\nip_check_mc_rcu(). This attempts to acquire &im->lock while &pmc->lock\nis already held on the same CPU, triggering a lockdep recursive locking\nwarning / deadlock.\n\nFix this by converting IPv4 struct ip_sf_list to RCU, mirroring the\nIPv6 implementation in net/ipv6/mcast.c:\n\n1. Add struct rcu_head to struct ip_sf_list and annotate sf_next,\n sources, and tomb as __rcu pointers.\n2. Use rcu_assign_pointer() and kfree_rcu() for list updates and\n deletions.\n3. Remove spin_lock_bh(&im->lock) from ip_check_mc_rcu() and traverse\n im->sources locklessly with for_each_psf_rcu(), reading and writing\n counter fields with READ_ONCE() and WRITE_ONCE().\n\nNote: RCU conversion of /proc/net/mcfilter will be done in a\nseparate patch."
}
],
"lastModified": "2026-09-30T14:10:59.253",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}