In the Linux kernel, the following vulnerability has been resolved:
ipv6: mcast: use rcu_assign_pointer() for __rcu list updates
Several places in net/ipv6/mcast.c update RCU-protected lists (np->ipv6_mc_list, idev->mc_list, idev->mc_tomb) using direct pointer assignments instead of rcu_assign_pointer():
- In __ipv6_dev_mc_dec(), unlinking a group from idev->mc_list did:
- In ipv6_sock_mc_drop() and __ipv6_sock_mc_close(), unlinking a group
- In __ipv6_sock_mc_join(), mc_lst->next was initialized to
- In mld_del_delrec() and __ipv6_dev_mc_inc(), __rcu source pointers
Fix these by consistently using rcu_assign_pointer() along with mc_dereference() / sock_dereference().