CVE-2026-72435

Source
https://cve.org/CVERecord?id=CVE-2026-72435
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72435.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72435
Downstream
Published
2026-08-15T05:56:49Z
Modified
2026-08-18T03:56:55Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()

Sashiko pointed out that kfree_rcu() was called before rcu_assign_pointer() in handling the comment extension. Fix the order so that rcu_assign_pointer() called first.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72435.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b57b2d1fa53fe8563bdfc66a33b844463b9af285
Fixed
c9787d7c24ffd83019f379455e1b97fb4f0f75eb
Fixed
6e98407cb94e035bba98956adc9096a76d8b2a9f
Fixed
50b70f56f3baaff46599f59b2d93fa2540120776
Fixed
d01b4b471f0fc5c396af62845e972ccf99cee29a
Fixed
fcb565966534909377a16be5f7b065db2e25c8b5
Fixed
8087bb360a936a6314d22b567e4b861656943eb6
Fixed
93a775fd67f3ef34949a9523bfa69403ee74efdd
Fixed
3ca9982a8882470aa0ac4e8bb9a552b181d1efcd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72435.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72435.json"