CVE-2026-74406

Source
https://cve.org/CVERecord?id=CVE-2026-74406
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74406.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74406
Downstream
Published
2026-08-15T05:59:15.385Z
Modified
2026-08-18T03:56:57.584071124Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
Details

In the Linux kernel, the following vulnerability has been resolved:

vxlan: Fix potential null-ptr-deref in vxlangroprepare_receive().

udptunnelsockrelease() could set sk->skuserdata to NULL while vxlangropreparereceive() is running.

Let's check if rcudereferenceskuserdata() is NULL after skbgroremcsum_init().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74406.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5602c48cf87562c2f95b831d690631935e834295
Fixed
9c58c729d32e7cea5772cc44929c6cd61e5a31cd
Fixed
f79c80f173fda9545b220c1f094b65fc06c252d0
Fixed
08f40c0d23c67c3aa4224c3311e134999c721fb4
Fixed
4a8cde6f7281ea2c4c290f9ad9923b3631defceb
Fixed
ef44dac2a37f86eeae6b88ed10a6d60b35387dfd
Fixed
30a45c0bffdd62350261e2f2689fdba426a33578

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74406.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74406.json"