CVE-2026-74288

Source
https://cve.org/CVERecord?id=CVE-2026-74288
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74288.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74288
Downstream
Published
2026-08-15T05:57:55Z
Modified
2026-08-18T03:56:56Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
Details

In the Linux kernel, the following vulnerability has been resolved:

net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().

rocker_router_fib_event() calls fib_rule_get() during RCU dump.

If the fib_rule is dying, refcount_inc() will complain about it.

Let's call refcount_inc_not_zero() in fib_rules_dump().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74288.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5d7bfd141924a5ece21eb612ad3c56612f041c1e
Fixed
0f929b59f4cd0e05bb1ecefe12b77e85911d4be2
Fixed
4b7ae30c81c2ee10a644749a3704a5c797ccc308
Fixed
2dfdc210d240bd48bb2ea746430b02b5571b6db9
Fixed
a7ef30753353ba6a95d693b1863a0214222a199a
Fixed
1fbc6c6efe78f4454a51afa0587efb6826f60f00
Fixed
bb4a5b3c91af3c8d705bb2e9f6f8069a70db26fc
Fixed
3af0bc1bd9039e2e50abf3e2d7fee411f38bce4e
Fixed
2821e85c058f81c9948a2fb1a634f7b47457d51c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74288.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74288.json"