{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  netlink: do not free nlk-\u003egroups while lockless readers can use it  netlink_realloc_groups() uses krealloc() under netlink_table_grab(). Whenever NLGRPSZ(groups) lands in a different kmalloc bucket, the old bitmap is freed immediately.  Two readers of nlk-\u003egroups / nlk-\u003engroups do not hold the netlink table lock:  1) sk_diag_dump_groups(). Hashed (bound) sockets are dumped from the    rhashtable walk in __netlink_diag_dump(), which only holds RCU.    Only the mc_list part of the dump takes nl_table_lock.  2) netlink_native_seq_show() (/proc/net/netlink), whose walk has been    lockless since commit 21e4902aea80 (\"netlink: Lockless lookup with    RCU grace period in socket release\").  Both can read a freed buffer, and sk_diag_dump_groups() can also read past the end of the old (smaller) buffer if it happens to load the old @groups pointer together with the new @ngroups value, copying the result into a NETLINK_DIAG_GROUPS attribute.  This is the same class of bug that commit f773608026ee (\"netlink: access nlk groups safely in netlink bind and getname\") fixed for bind() and getname(); these two readers were missed. Simply grabbing the table lock in sk_diag_dump_groups() is not an option, because it is also called with nl_table_lock already held from the mc_list section of the dump.  Make the lockless readers safe instead:  - Allocate a new bitmap and free the old one after an RCU grace period,   instead of relying on the implicit kfree() done by krealloc().  - Publish @groups before @ngroups, both with release semantics, and have   the lockless readers load @ngroups first. A reader can then never pair   the new (bigger) size with the old (smaller) buffer, and a reader   picking up the new pointer while still seeing the old size is   guaranteed to see the initialized bitmap.  netlink_realloc_groups() is called from process context (bind() and setsockopt()), so kfree_rcu_mightsleep() can be used, once the table has been released.",
  "id": "DEBIAN-CVE-2026-98284",
  "modified": "2026-10-07T04:47:36.823717481Z",
  "published": "2026-10-06T09:18:18.480Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98284"
    }
  ],
  "upstream": [
    "CVE-2026-98284"
  ]
}