CVE-2026-98102

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src() When removing a source filter whose count reaches zero, ip6_mc_del1_src() unlinks psf from pmc->mca_sources. If the filter was previously active, the code moved psf directly into pmc->mca_tomb by updating psf->sf_next. Because pmc->mca_sources is traversed locklessly under RCU (e.g. by ipv6_chk_mcast_addr()), mutating psf->sf_next before a grace period elapses diverts concurrent readers to the tombstone list. Consequently, readers miss remaining active sources in pmc->mca_sources and improperly examine deleted tombstone entries. Fix this by allocating a new tombstone node for pmc->mca_tomb (as done in sf_setstate()) and retiring the original psf via kfree_rcu().

Package Linux Kernel
Published 2026-09-25
Last modified 2026-10-03
Patch available
Yes

Affected versions

Linux kernel versions 5.10.261, 5.13 and later are affected. Fixed in 6.6.158, 6.12.111, 6.18.53, 7.2.7, 7.3-rc2 and their respective stable series.

Affected from
≥ 5.10.261 ≥ 5.13
Fixed in
✓ 6.6.158 6.6.x ✓ 6.12.111 6.12.x ✓ 6.18.53 6.18.x ✓ 7.2.7 7.2.x ✓ 7.3-rc2

Frequently asked questions

  • What is CVE-2026-98102?

    CVE-2026-98102 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.10.261 onward and has been patched in 6.6.158, 6.12.111, 6.18.53 and others. CVE-2026-98102 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-98102?

    Yes. CVE-2026-98102 has been patched. Fixed versions include 6.6.158, 6.12.111, 6.18.53 and others. If you are running Linux kernel 5.10.261 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-98102 actively exploited?

    No. CVE-2026-98102 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.