CVE-2026-98284
In the Linux kernel, the following vulnerability has been resolved:
netlink: do not free nlk->groups while lockless readers can use it
netlink_realloc_groups() uses krealloc() under netlink_table_grab(). Whenever NLGRPSZ(groups) lands in a different kmalloc bucket, the old bitmap is freed immediately.
Two readers of nlk->groups / nlk->ngroups do not hold the netlink table lock:
Both can read a freed buffer, and sk_diag_dump_groups() can also read past the end of the old (smaller) buffer if it happens to load the old @groups pointer together with the new @ngroups value, copying the result into a NETLINK_DIAG_GROUPS attribute.
Leer descripción completaMostrar menos
This is the same class of bug that commit f773608026ee ("netlink: access nlk groups safely in netlink bind and getname") fixed for bind() and getname(); these two readers were missed. Simply grabbing the table lock in sk_diag_dump_groups() is not an option, because it is also called with nl_table_lock already held from the mc_list section of the dump.
Make the lockless readers safe instead:
netlink_realloc_groups() is called from process context (bind() and setsockopt()), so kfree_rcu_mightsleep() can be used, once the table has been released.
Detalles técnicos trazas, registros y código del informe original
1) sk_diag_dump_groups(). Hashed (bound) sockets are dumped from the
rhashtable walk in __netlink_diag_dump(), which only holds RCU.
Only the mc_list part of the dump takes nl_table_lock.
2) netlink_native_seq_show() (/proc/net/netlink), whose walk has been
lockless since commit 21e4902aea80 ("netlink: Lockless lookup with
RCU grace period in socket release").
- Allocate a new bitmap and free the old one after an RCU grace period,
instead of relying on the implicit kfree() done by krealloc().
- Publish @groups before @ngroups, both with release semantics, and have
the lockless readers load @ngroups first. A reader can then never pair
the new (bigger) size with the old (smaller) buffer, and a reader
picking up the new pointer while still seeing the old size is
guaranteed to see the initialized bitmap.CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98284",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "21e4902aea80ef35afc00ee8d2abdea4f519b7f7",
"lessThan": "22f313e211d58a66786c81487c3905fa5d4b2a8f",
"versionType": "git"
},
{
"status": "affected",
"version": "21e4902aea80ef35afc00ee8d2abdea4f519b7f7",
"lessThan": "ceac0de741bfb47ca255eee075257b3bb31f0651",
"versionType": "git"
}
],
"programFiles": [
"net/netlink/af_netlink.c",
"net/netlink/diag.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.0"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/netlink/af_netlink.c",
"net/netlink/diag.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:18.480",
"references": [
{
"url": "https://git.kernel.org/stable/c/22f313e211d58a66786c81487c3905fa5d4b2a8f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ceac0de741bfb47ca255eee075257b3bb31f0651",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlink: do not free nlk->groups while lockless readers can use it\n\nnetlink_realloc_groups() uses krealloc() under netlink_table_grab().\nWhenever NLGRPSZ(groups) lands in a different kmalloc bucket, the old\nbitmap is freed immediately.\n\nTwo readers of nlk->groups / nlk->ngroups do not hold the netlink\ntable lock:\n\n1) sk_diag_dump_groups(). Hashed (bound) sockets are dumped from the\n rhashtable walk in __netlink_diag_dump(), which only holds RCU.\n Only the mc_list part of the dump takes nl_table_lock.\n\n2) netlink_native_seq_show() (/proc/net/netlink), whose walk has been\n lockless since commit 21e4902aea80 (\"netlink: Lockless lookup with\n RCU grace period in socket release\").\n\nBoth can read a freed buffer, and sk_diag_dump_groups() can also read\npast the end of the old (smaller) buffer if it happens to load the old\n@groups pointer together with the new @ngroups value, copying the\nresult into a NETLINK_DIAG_GROUPS attribute.\n\nThis is the same class of bug that commit f773608026ee (\"netlink:\naccess nlk groups safely in netlink bind and getname\") fixed for bind()\nand getname(); these two readers were missed. Simply grabbing the table\nlock in sk_diag_dump_groups() is not an option, because it is also\ncalled with nl_table_lock already held from the mc_list section of the\ndump.\n\nMake the lockless readers safe instead:\n\n- Allocate a new bitmap and free the old one after an RCU grace period,\n instead of relying on the implicit kfree() done by krealloc().\n\n- Publish @groups before @ngroups, both with release semantics, and have\n the lockless readers load @ngroups first. A reader can then never pair\n the new (bigger) size with the old (smaller) buffer, and a reader\n picking up the new pointer while still seeing the old size is\n guaranteed to see the initialized bitmap.\n\nnetlink_realloc_groups() is called from process context (bind() and\nsetsockopt()), so kfree_rcu_mightsleep() can be used, once the table\nhas been released."
}
],
"lastModified": "2026-10-06T09:18:18.480",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}