Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: make sure gc is properly stopped

Sashiko noticed that when destroying a set,
cancel_delayed_work_sync() was called while gc
calls queue_delayed_work() unconditionally which
can lead not to properly shutting down the gc.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The netfilter ipset subsystem in the Linux kernel contains a race condition that arises when an IP set is destroyed. The code cancels scheduled garbage‑collector work but subsequently posts new work without verifying that it has been cancelled, which can leave the garbage collector running after the set has been released. This improper shutdown can cause kernel instability or a crash, resulting in a denial‑of‑service to the affected system.

Affected Systems

All Linux kernel releases prior to incorporating commit 12088da6 in the netfilter ipset code are affected. Kernels that include this commit or later versions contain the fix and are no longer vulnerable. The vulnerability applies to all mainstream distributions based on those kernel versions unless they have applied this patch separately.

Risk and Exploitability

The EPSS score of < 1 % indicates that the likelihood of exploitation is very low. The CVSS score of 7.8 reflects a high severity adverse impact. The flaw is not listed in the CISA KEV catalog and no public exploits have been reported. Exploitation would require an attacker to perform privileged ipset operations, which typically needs root or administrative access. Based on the description, this prerequisite is inferred rather than explicitly stated. If ipset commands are exposed to untrusted users or processes, the risk would increase; otherwise the threat remains limited to trusted administrators but still poses a risk due to the potential kernel crash.

Generated by OpenCVE AI on August 22, 2026 at 03:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes commit 12088da6 or newer.
  • Reboot the system after the kernel update to load the patched code.
  • If a kernel upgrade cannot be applied immediately, limit ipset usage to trusted administrators, disable the ipset module when unnecessary, and monitor kernel logs for garbage‑collector errors or crashes.

Generated by OpenCVE AI on August 22, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-821
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: make sure gc is properly stopped Sashiko noticed that when destroying a set, cancel_delayed_work_sync() was called while gc calls queue_delayed_work() unconditionally which can lead not to properly shutting down the gc.
Title netfilter: ipset: make sure gc is properly stopped
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:44:09.822Z

Reserved: 2026-08-09T03:40:39.929Z

Link: CVE-2026-72434

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:17.247

Modified: 2026-08-17T06:19:10.710

Link: CVE-2026-72434

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72434 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T03:30:16Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-821

    Incorrect Synchronization