« Volver al listado

CVE-2026-98284

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

netlink: do not free nlk->groups while lockless readers can use it

netlink_realloc_groups() uses krealloc() under netlink_table_grab(). Whenever NLGRPSZ(groups) lands in a different kmalloc bucket, the old bitmap is freed immediately.

Two readers of nlk->groups / nlk->ngroups do not hold the netlink table lock:

Both can read a freed buffer, and sk_diag_dump_groups() can also read past the end of the old (smaller) buffer if it happens to load the old @groups pointer together with the new @ngroups value, copying the result into a NETLINK_DIAG_GROUPS attribute.

Leer descripción completaMostrar menos

This is the same class of bug that commit f773608026ee ("netlink: access nlk groups safely in netlink bind and getname") fixed for bind() and getname(); these two readers were missed. Simply grabbing the table lock in sk_diag_dump_groups() is not an option, because it is also called with nl_table_lock already held from the mc_list section of the dump.

Make the lockless readers safe instead:

netlink_realloc_groups() is called from process context (bind() and setsockopt()), so kfree_rcu_mightsleep() can be used, once the table has been released.

Detalles técnicos trazas, registros y código del informe original
1) sk_diag_dump_groups(). Hashed (bound) sockets are dumped from the
   rhashtable walk in __netlink_diag_dump(), which only holds RCU.
   Only the mc_list part of the dump takes nl_table_lock.

2) netlink_native_seq_show() (/proc/net/netlink), whose walk has been
   lockless since commit 21e4902aea80 ("netlink: Lockless lookup with
   RCU grace period in socket release").

- Allocate a new bitmap and free the old one after an RCU grace period,
  instead of relying on the implicit kfree() done by krealloc().

- Publish @groups before @ngroups, both with release semantics, and have
  the lockless readers load @ngroups first. A reader can then never pair
  the new (bigger) size with the old (smaller) buffer, and a reader
  picking up the new pointer while still seeing the old size is
  guaranteed to see the initialized bitmap.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98284",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "21e4902aea80ef35afc00ee8d2abdea4f519b7f7",
              "lessThan": "22f313e211d58a66786c81487c3905fa5d4b2a8f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "21e4902aea80ef35afc00ee8d2abdea4f519b7f7",
              "lessThan": "ceac0de741bfb47ca255eee075257b3bb31f0651",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/netlink/af_netlink.c",
            "net/netlink/diag.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/netlink/af_netlink.c",
            "net/netlink/diag.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:18.480",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/22f313e211d58a66786c81487c3905fa5d4b2a8f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ceac0de741bfb47ca255eee075257b3bb31f0651",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlink: do not free nlk->groups while lockless readers can use it\n\nnetlink_realloc_groups() uses krealloc() under netlink_table_grab().\nWhenever NLGRPSZ(groups) lands in a different kmalloc bucket, the old\nbitmap is freed immediately.\n\nTwo readers of nlk->groups / nlk->ngroups do not hold the netlink\ntable lock:\n\n1) sk_diag_dump_groups(). Hashed (bound) sockets are dumped from the\n   rhashtable walk in __netlink_diag_dump(), which only holds RCU.\n   Only the mc_list part of the dump takes nl_table_lock.\n\n2) netlink_native_seq_show() (/proc/net/netlink), whose walk has been\n   lockless since commit 21e4902aea80 (\"netlink: Lockless lookup with\n   RCU grace period in socket release\").\n\nBoth can read a freed buffer, and sk_diag_dump_groups() can also read\npast the end of the old (smaller) buffer if it happens to load the old\n@groups pointer together with the new @ngroups value, copying the\nresult into a NETLINK_DIAG_GROUPS attribute.\n\nThis is the same class of bug that commit f773608026ee (\"netlink:\naccess nlk groups safely in netlink bind and getname\") fixed for bind()\nand getname(); these two readers were missed. Simply grabbing the table\nlock in sk_diag_dump_groups() is not an option, because it is also\ncalled with nl_table_lock already held from the mc_list section of the\ndump.\n\nMake the lockless readers safe instead:\n\n- Allocate a new bitmap and free the old one after an RCU grace period,\n  instead of relying on the implicit kfree() done by krealloc().\n\n- Publish @groups before @ngroups, both with release semantics, and have\n  the lockless readers load @ngroups first. A reader can then never pair\n  the new (bigger) size with the old (smaller) buffer, and a reader\n  picking up the new pointer while still seeing the old size is\n  guaranteed to see the initialized bitmap.\n\nnetlink_realloc_groups() is called from process context (bind() and\nsetsockopt()), so kfree_rcu_mightsleep() can be used, once the table\nhas been released."
    }
  ],
  "lastModified": "2026-10-06T09:18:18.480",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}