Linux Kernel Data Race Vulnerability in IPv4 Multipath Hash Policy Handling

Vulnerability

A data race vulnerability has been identified in the Linux kernel's IPv4 handling of the sysctl_fib_multipath_hash_policy. This vulnerability arises because the hash policy can be changed concurrently while it is being read, leading to potential inconsistencies. To address this issue, the kernel has been updated to include a READ_ONCE() directive in the readers of this policy.

Impact

Exploitation of this vulnerability could lead to inconsistent reads of the sysctl_fib_multipath_hash_policy, potentially causing incorrect behavior in applications or system components that rely on this configuration.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.