Deadlock in Linux kernel - CVE-2026-98103
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to recursive locking in ip_check_mc_rcu() when generating IGMPv3 reports while an XFRM policy matches a multicast destination. A local user can trigger IGMPv3 report generation to cause a denial of service.
The affected function is used in packet receive and route lookup RCU fast paths.