Executive brief
A vulnerability was identified in the Linux kernel's networking subsystem, specifically within the ipset utility used for managing firewall rules. A race condition allows a local attacker to trigger a system crash or potentially execute unauthorized code by manipulating IP set lists while they are being exported. This could lead to a complete denial of service or unauthorized access to sensitive system memory.
Technical details
A use-after-free vulnerability exists in the Linux kernel netfilter ipset component due to a race condition between ip_set_dump_do/ip_set_dump_done and ip_set_list resizing. The dump functions access the ip_set_list array via ip_set_ref_netlink() without proper RCU read-side critical sections or mutex protection. If a concurrent ip_set_create() operation triggers an array resize, it may free the old array while the dump process is still indexing into it. This results in a slab-use-after-free, which can be observed as a KASAN-detected invalid memory access or a general protection fault leading to a kernel panic. The fix involves wrapping the affected array loads in rcu_read_lock() and rcu_read_unlock() to ensure the array is not freed during the dump operation.
Affected products
- Linux Linux Kernel 4.19.5 to 7.1
Timeline
- 2026-06-24: disclosed: Vulnerability reported by Weiming Shi
- 2026-06-30: patched: Initial patch committed to stable tree
- 2026-07-20: advisory: NVD publication date