Race condition in Linux kernel - CVE-2026-98099
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger a race condition.
The vulnerability exists due to improper synchronization in IPv6 multicast RCU-protected list management in net/ipv6/mcast.c when concurrently modifying IPv6 multicast group memberships while lockless readers traverse the lists. A local user can modify IPv6 multicast group memberships concurrently with list traversal to trigger a race condition.