Race condition in Linux kernel - CVE-2026-72436
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in netfilter ipset hash types when lockless RCU readers process set data in parallel with add, delete, or garbage-collection operations. A local user can trigger concurrent ipset operations to cause a denial of service.
The issue affects readers that are not protected by the region lock and are not in set destroy or new or temporary set creation phases.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)
How to mitigate CVE-2026-72436
linux (Ubuntu package) - addressed in versions 7.0.0-34.34, 7.0.0-34.34.1, 7.0.0-34.34~24.04.1, 7.0.0-1012.12~24.04.1, 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14, 7.0.0-1020.20
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14
External References
- https://git.kernel.org/stable/c/3219d74e4536658c937fd878a327257b86ce80dd
- https://git.kernel.org/stable/c/6329d3a9afe715fddda0460cfa46b496d61c2fe0
- https://git.kernel.org/stable/c/7445fe965b7d8756070a40e80f8b73348ccda1d7
- https://git.kernel.org/stable/c/c107233d2ff4fd7cef5d02f9124b99194957a710
- https://git.kernel.org/stable/c/c4d257734e91bfcdc71d41843392dd6400b5bb1b
- https://git.kernel.org/stable/c/e4b4984e28c16406ecb318444dea4a8bf47def3e