PatchSiren cyber security CVE debrief
CVE-2026-98102 Linux CVE debrief
A vulnerability in the Linux kernel's IPv6 multicast functionality has been addressed. The issue, resolved in CVE-2026-98102, involves improper handling of source filters in the ip6_mc_del1_src() function, which could lead to incorrect results when traversing the list of multicast sources under RCU. This could potentially cause issues with concurrent readers.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Linux kernel maintainers, administrators of Linux-based systems, security teams responsible for patching and vulnerability management, and operators of Linux-based infrastructure should verify and apply patches. These individuals and teams should review Linux kernel IPv6 multicast configurations for potential exposure and ensure that compensating controls are in place while remediation is scheduled and verified. Vulnerability management and security teams,
Why it matters
A vulnerability in the Linux kernel's IPv6 multicast functionality has been addressed. The issue involves improper handling of source filters, which could lead to incorrect results when traversing the list of multicast sources under RCU. Linux kernel maintainers, administrators of Linux-based systems, and security teams should verify and apply patches.
- Verification of Linux kernel versions and patch application is necessary
- Potential for incorrect results when traversing multicast sources under RCU
Technical summary
The Linux kernel's IPv6 multicast functionality had a vulnerability in the ip6_mc_del1_src() function, which involved improper handling of source filters. This could lead to incorrect results when traversing the list of multicast sources under RCU. The issue has been resolved through patching, and Linux kernel maintainers, administrators, and security teams should verify and apply patches to prevent potential issues with concurrent readers. Affected systems may experience incorrect results when traversing multicast sources, and defenders should review and apply patches to ensure proper functionality.
Defensive priority
Medium
Recommended defensive actions
- Review Linux kernel IPv6 multicast configurations for potential exposure
- Verify and apply patches for the Linux kernel
- Monitor for updates from the Linux kernel maintainers
- Perform a thorough review of the Linux kernel's IPv6 multicast functionality
- Verify Linux kernel versions and patch application
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and source metadata indicate a vulnerability in the Linux kernel's IPv6 multicast functionality. The issue has been resolved, but details on affected versions and exploitation are limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-98102 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-98102
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-98102 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-98102
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4352737297b262e8367675c19a7dc6a9f53c97af
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5149c60c406595b56fda0c6e9aae7fd287f636aa
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8d4fe5c13f5056faa6deb09a90e24a89f9ebfad4
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/93b49239840b91313adbd77b8b52993eff2d08c1
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.