SB20260815285 - Race condition in Linux kernel netfilter ipset
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-72436)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in netfilter ipset hash types when lockless RCU readers process set data in parallel with add, delete, or garbage-collection operations. A local user can trigger concurrent ipset operations to cause a denial of service.
The issue affects readers that are not protected by the region lock and are not in set destroy or new or temporary set creation phases.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3219d74e4536658c937fd878a327257b86ce80dd
- https://git.kernel.org/stable/c/6329d3a9afe715fddda0460cfa46b496d61c2fe0
- https://git.kernel.org/stable/c/7445fe965b7d8756070a40e80f8b73348ccda1d7
- https://git.kernel.org/stable/c/c107233d2ff4fd7cef5d02f9124b99194957a710
- https://git.kernel.org/stable/c/c4d257734e91bfcdc71d41843392dd6400b5bb1b
- https://git.kernel.org/stable/c/e4b4984e28c16406ecb318444dea4a8bf47def3e