{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "21e4902aea80ef35afc00ee8d2abdea4f519b7f7"
            },
            {
              "fixed": "22f313e211d58a66786c81487c3905fa5d4b2a8f"
            },
            {
              "fixed": "ceac0de741bfb47ca255eee075257b3bb31f0651"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.0.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98284.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlink: do not free nlk-\u003egroups while lockless readers can use it\n\nnetlink_realloc_groups() uses krealloc() under netlink_table_grab().\nWhenever NLGRPSZ(groups) lands in a different kmalloc bucket, the old\nbitmap is freed immediately.\n\nTwo readers of nlk-\u003egroups / nlk-\u003engroups do not hold the netlink\ntable lock:\n\n1) sk_diag_dump_groups(). Hashed (bound) sockets are dumped from the\n   rhashtable walk in __netlink_diag_dump(), which only holds RCU.\n   Only the mc_list part of the dump takes nl_table_lock.\n\n2) netlink_native_seq_show() (/proc/net/netlink), whose walk has been\n   lockless since commit 21e4902aea80 (\"netlink: Lockless lookup with\n   RCU grace period in socket release\").\n\nBoth can read a freed buffer, and sk_diag_dump_groups() can also read\npast the end of the old (smaller) buffer if it happens to load the old\n@groups pointer together with the new @ngroups value, copying the\nresult into a NETLINK_DIAG_GROUPS attribute.\n\nThis is the same class of bug that commit f773608026ee (\"netlink:\naccess nlk groups safely in netlink bind and getname\") fixed for bind()\nand getname(); these two readers were missed. Simply grabbing the table\nlock in sk_diag_dump_groups() is not an option, because it is also\ncalled with nl_table_lock already held from the mc_list section of the\ndump.\n\nMake the lockless readers safe instead:\n\n- Allocate a new bitmap and free the old one after an RCU grace period,\n  instead of relying on the implicit kfree() done by krealloc().\n\n- Publish @groups before @ngroups, both with release semantics, and have\n  the lockless readers load @ngroups first. A reader can then never pair\n  the new (bigger) size with the old (smaller) buffer, and a reader\n  picking up the new pointer while still seeing the old size is\n  guaranteed to see the initialized bitmap.\n\nnetlink_realloc_groups() is called from process context (bind() and\nsetsockopt()), so kfree_rcu_mightsleep() can be used, once the table\nhas been released.",
  "id": "CVE-2026-98284",
  "modified": "2026-10-08T02:31:01.971593290Z",
  "published": "2026-10-06T08:45:45.443Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/22f313e211d58a66786c81487c3905fa5d4b2a8f"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ceac0de741bfb47ca255eee075257b3bb31f0651"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98284.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98284"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "netlink: do not free nlk-\u003egroups while lockless readers can use it"
}