Race condition in Linux kernel - CVE-2026-98101

 

Race condition in Linux kernel - CVE-2026-98101

Published: September 28, 2026


Vulnerability identifier: #VU152363
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-98101
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause IPv6 multicast packets to be evaluated against incorrect source filters.

The vulnerability exists due to a race condition in the ip6_mc_source() IPv6 multicast source-filter handling function when source filters are modified concurrently with packet reception. A local user can concurrently add or remove IPv6 multicast source filters to cause IPv6 multicast packets to be evaluated against incorrect source filters.

The race affects UDP and raw multicast receive paths.


Affected software

Linux kernel

How to mitigate CVE-2026-98101

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins