GHSA-6x4x-6p4p-6f5fCriticalCVSS 9.8

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Don't use...

Published
August 15, 2026
Last Modified
August 17, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types

Sashiko pointed out that there are a few lockless RCU readers using test_bit() which is a relaxed atomic operation and provides no memory barrier guarantees. Use test_bit_acquire() instead where the operation may run parallel with add/del/gc, i.e. is not one from the next cases

  • protected by region lock
  • in a set destroy phase
  • in a new/temporary set creation phase

🔗 References (8)