CVE-2026-72435
unknown
CVSS v3
—
CVSS v4 NEW
—
VIR risk
—
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() Sashiko pointed out that kfree_rcu() was called before rcu_assign_pointer() in handling the comment extension. Fix the order so that rcu_assign_pointer() called first.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/3ca9982a8882470aa0ac4e8bb9a552b181d1efcd
- https://git.kernel.org/stable/c/50b70f56f3baaff46599f59b2d93fa2540120776
- https://git.kernel.org/stable/c/6e98407cb94e035bba98956adc9096a76d8b2a9f
- https://git.kernel.org/stable/c/8087bb360a936a6314d22b567e4b861656943eb6
- https://git.kernel.org/stable/c/93a775fd67f3ef34949a9523bfa69403ee74efdd
- https://git.kernel.org/stable/c/c9787d7c24ffd83019f379455e1b97fb4f0f75eb
- https://git.kernel.org/stable/c/d01b4b471f0fc5c396af62845e972ccf99cee29a
- https://git.kernel.org/stable/c/fcb565966534909377a16be5f7b065db2e25c8b5
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.