CVE-2026-74478

Source
https://cve.org/CVERecord?id=CVE-2026-74478
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74478.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74478
Downstream
Published
2026-08-15T12:27:12.549Z
Modified
2026-08-17T03:54:57.761544374Z
Summary
um: vector: fix use-after-free in vector_mmsg_rx()
Details

In the Linux kernel, the following vulnerability has been resolved:

um: vector: fix use-after-free in vectormmsgrx()

When vectormmsgrx() discards a packet whose overlay header fails verify_header(), it frees the skb and continues the loop:

if (header_check < 0) {
    dev_kfree_skb_irq(skb);
    vp->estats.rx_encaps_errors++;
    continue;
}

The normal and short-packet paths fall through to the bottom of the loop body, which clears the consumed slot and advances the cursors:

(*skbuff_vector) = NULL;
mmsg_vector++;
skbuff_vector++;

The verifyheader() < 0 path skips that via continue, so the freed skb is left in skbuffvector[] and the cursors do not advance. The next iteration reads the same slot, gets the freed skb, and frees it again, producing a refcount underflow / use-after-free in the RX path.

Discard the slot the same way the other paths do before continuing.

Only transports whose verify_header() can return negative are affected: GRE and L2TPv3 do so on a cookie/session-id mismatch (raw/tap do not), so any peer on such a transport can trigger it without authentication.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74478.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
49da7e64f33e80edffb1a9eeb230fa4c3f42dffb
Fixed
4b9601595e8b6b5d18878cac0aeabc687d241111
Fixed
67d58ab4f2ccf7145f3da07e025735a09c79de1b
Fixed
180ff4c81faf01ec4e06082c9daa7c40518ead89
Fixed
804b681002ead233abf49a3efd681f5468a835f9
Fixed
af421e9aed3920c7ac88c24daa48606c7112feca

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74478.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.17.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74478.json"