{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98099","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:19:56.077Z","datePublished":"2026-09-25T10:24:28.929Z","dateUpdated":"2026-09-25T10:24:28.929Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-25T10:24:28.929Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: use rcu_assign_pointer() for __rcu list updates\n\nSeveral places in net/ipv6/mcast.c update RCU-protected lists\n(np->ipv6_mc_list, idev->mc_list, idev->mc_tomb) using direct pointer\nassignments instead of rcu_assign_pointer():\n\n1. In __ipv6_dev_mc_dec(), unlinking a group from idev->mc_list did:\n       *map = ma->next;\n   without rcu_assign_pointer() while concurrent readers traverse\n   idev->mc_list locklessly under rcu_read_lock().\n2. In ipv6_sock_mc_drop() and __ipv6_sock_mc_close(), unlinking a group\n   from np->ipv6_mc_list directly assigned *lnk = mc_lst->next and\n   np->ipv6_mc_list = mc_lst->next without rcu_assign_pointer(), racing\n   with lockless readers in inet6_mc_check().\n3. In __ipv6_sock_mc_join(), mc_lst->next was initialized to\n   np->ipv6_mc_list via raw assignment before publishing mc_lst.\n4. In mld_del_delrec() and __ipv6_dev_mc_inc(), __rcu source pointers\n   passed into rcu_assign_pointer() lacked explicit dereference helpers.\n\nFix these by consistently using rcu_assign_pointer() along with\nmc_dereference() / sock_dereference()."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ipv6/mcast.c"],"versions":[{"version":"456b61bca8ee324ab6c18b065e632c9a8c88aa39","lessThan":"2e46b0c9fcf7e10b64ce1630b925f47918d1f7f6","status":"affected","versionType":"git"},{"version":"456b61bca8ee324ab6c18b065e632c9a8c88aa39","lessThan":"0c8f56c583c3250408367880c98e4d6fbc929315","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ipv6/mcast.c"],"versions":[{"version":"2.6.38","status":"affected"},{"version":"0","lessThan":"2.6.38","status":"unaffected","versionType":"semver"},{"version":"7.2.7","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"7.2.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"7.3-rc2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/2e46b0c9fcf7e10b64ce1630b925f47918d1f7f6"},{"url":"https://git.kernel.org/stable/c/0c8f56c583c3250408367880c98e4d6fbc929315"}],"title":"ipv6: mcast: use rcu_assign_pointer() for __rcu list updates","x_generator":{"engine":"bippy-1.2.0"}}}}