---
id: CVE-2026-98284
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netlink: do not free nlk->groups while lockless readers can use it

  netlink_realloc_groups() uses krealloc() under netlink_table_grab().
  Whenever NLGRPSZ(groups) lands …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netlink: do not free nlk->groups while lockless readers can use it

  netlink_realloc_groups() uses krealloc() under netlink_table_grab().
  Whenever NLGRPSZ(groups) lands …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 21e4902aea80ef35afc00ee8d2abdea4f519b7f7 <
    22f313e211d58a66786c81487c3905fa5d4b2a8f
  - >-
    Linux >= 21e4902aea80ef35afc00ee8d2abdea4f519b7f7 <
    ceac0de741bfb47ca255eee075257b3bb31f0651
  - Linux 4.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:18.480'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98284'
references:
  - url: 'https://git.kernel.org/stable/c/22f313e211d58a66786c81487c3905fa5d4b2a8f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ceac0de741bfb47ca255eee075257b3bb31f0651'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.420Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

netlink: do not free nlk->groups while lockless readers can use it

netlink_realloc_groups() uses krealloc() under netlink_table_grab().
Whenever NLGRPSZ(groups) lands in a different kmalloc bucket, the old
bitmap is freed immediately.

Two readers of nlk->groups / nlk->ngroups do not hold the netlink
table lock:

1) sk_diag_dump_groups(). Hashed (bound) sockets are dumped from the
   rhashtable walk in __netlink_diag_dump(), which only holds RCU.
   Only the mc_list part of the dump takes nl_table_lock.

2) netlink_native_seq_show() (/proc/net/netlink), whose walk has been
   lockless since commit 21e4902aea80 ("netlink: Lockless lookup with
   RCU grace period in socket release").

Both can read a freed buffer, and sk_diag_dump_groups() can also read
past the end of the old (smaller) buffer if it happens to load the old
@groups pointer together with the new @ngroups value, copying the
result into a NETLINK_DIAG_GROUPS attribute.

This is the same class of bug that commit f773608026ee ("netlink:
access nlk groups safely in netlink bind and getname") fixed for bind()
and getname(); these two readers were missed. Simply grabbing the table
lock in sk_diag_dump_groups() is not an option, because it is also
called with nl_table_lock already held from the mc_list section of the
dump.

Make the lockless readers safe instead:

- Allocate a new bitmap and free the old one after an RCU grace period,
  instead of relying on the implicit kfree() done by krealloc().

- Publish @groups before @ngroups, both with release semantics, and have
  the lockless readers load @ngroups first. A reader can then never pair
  the new (bigger) size with the old (smaller) buffer, and a reader
  picking up the new pointer while still seeing the old size is
  guaranteed to see the initialized bitmap.

netlink_realloc_groups() is called from process context (bind() and
setsockopt()), so kfree_rcu_mightsleep() can be used, once the table
has been released.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
