Race condition in Linux kernel - CVE-2026-72436

 

Race condition in Linux kernel - CVE-2026-72436

Published: August 15, 2026


Vulnerability identifier: #VU143004
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72436
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in netfilter ipset hash types when lockless RCU readers process set data in parallel with add, delete, or garbage-collection operations. A local user can trigger concurrent ipset operations to cause a denial of service.

The issue affects readers that are not protected by the region lock and are not in set destroy or new or temporary set creation phases.


Affected software

Linux kernel
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)

How to mitigate CVE-2026-72436

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 7.0.0-34.34, 7.0.0-34.34.1, 7.0.0-34.34~24.04.1, 7.0.0-1012.12~24.04.1, 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14, 7.0.0-1020.20
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14

External References

Related Security Bulletins