Executive brief
The Linux kernel's netfilter ipset component, which manages network address filtering rules, contains a race condition in its packet filtering logic. When multiple concurrent operations access filtering rules without proper synchronization, data corruption or security policy bypasses could occur, potentially allowing unauthorized network traffic to pass through firewall rules or causing system instability.
Technical details
The vulnerability is a race condition in netfilter ipset's hash table implementation, specifically in lockless RCU (Read-Copy-Update) reader code paths. The affected code uses test_bit(), a relaxed atomic operation without memory barrier guarantees, when reading hash table state in contexts that may run concurrently with add/delete/garbage collection operations. This lack of synchronization can cause readers to observe stale data or miss updates to the hash table's used-slot bitmap. The fix replaces test_bit() with test_bit_acquire() to provide proper memory ordering semantics. Attack vectors include network packets triggering concurrent ipset lookups, with no authentication required. A successful exploit could corrupt firewall policy enforcement or cause denial of service.
Affected products
- Linux Linux kernel Linux 4.14 through 7.2 (affected in netfilter ipset component)
Timeline
- 2026-08-15: disclosed
- 2026-06-17: patched: Fix committed upstream; backported to stable branches