๐Ÿ” CVE Alert

CVE-2026-98101

UNKNOWN 0.0

ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source() pmc->sflist is read locklessly under rcu_read_lock() by inet6_mc_check() during packet reception in the UDP and RAW multicast receive paths. ip6_mc_source() mutated psl->sl_addr and psl->sl_count in-place when adding or removing a source filter. Additionally, when expanding the filter buffer, newpsl was published via rcu_assign_pointer() before writing the new source into the array. Because 16-byte struct in6_addr writes are not atomic and array shifting is not synchronized with RCU readers, concurrent readers in inet6_mc_check() could read torn IPv6 addresses or observe duplicated/missed source entries. Fix this by switching ip6_mc_source() to copy-on-write RCU updates: allocate and fully populate newpsl before publishing it via rcu_assign_pointer(), and reclaim the old filter via kfree_rcu(), matching ip6_mc_msfilter(). Also remove the now unused IP6_SFBLOCK macro.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
882ba1f73c06831f2a21044ebd8864c485ac04f2 < 2c2091e2ee93049fc513ad1e6c99d8b6c809f467 882ba1f73c06831f2a21044ebd8864c485ac04f2 < 20db91a052332ef5552bd2f651ffb9db911cf67b 882ba1f73c06831f2a21044ebd8864c485ac04f2 < c073d1b070f171d206b19c98d71739a97f15b3f1 47c75e3923c8d562fea8daf0ccf31546a7bef0ea 5.10.261 < 5.11
Linux / Linux
5.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/2c2091e2ee93049fc513ad1e6c99d8b6c809f467 git.kernel.org: https://git.kernel.org/stable/c/20db91a052332ef5552bd2f651ffb9db911cf67b git.kernel.org: https://git.kernel.org/stable/c/c073d1b070f171d206b19c98d71739a97f15b3f1