Linux Kernel IGMP Sysctl Data-Race Vulnerability

Vulnerability

A data-race vulnerability has been identified in the Linux kernel's IGMP (Internet Group Management Protocol) implementation. The issue arises around the sysctl_igmp_qrv variable, which can be modified concurrently while being read. This vulnerability affects several versions of the Linux kernel.

Impact

Exploitation of this vulnerability can lead to inconsistent or unexpected behavior in the IGMP protocol handling, potentially causing issues in network communication or multicast group management.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.