CVE-2026-74548

Source
https://cve.org/CVERecord?id=CVE-2026-74548
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74548.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74548
Downstream
Published
2026-08-15T12:27:56Z
Modified
2026-08-21T03:30:34Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
forcedeth: fix UAF of txrx_stats in nv_remove
Details

In the Linux kernel, the following vulnerability has been resolved:

forcedeth: fix UAF of txrx_stats in nv_remove

nv_remove() frees the per-CPU txrx_stats before unregister_netdev(). Until unregister completes, ndo_get_stats64, the NAPI/xmit data path, and nv_close()/drain may still access txrx_stats, leading to a use-after-free.

Free the stats only after unregister_netdev().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74548.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f4b633b911fd3b4cbe1dc065e8fb064078d0889d
Fixed
cdf864d5d3c813ae1876f2bacc1cf3ac3c66dfc9
Fixed
7c22b4ee0bd003cecfc14ca28981cb213e201f70
Fixed
d51ce7a63b76eda02cabfed1b0cc277b2f5c9bcc
Fixed
cf2dcde2284562ff87830ca0b7fa2b06e95aef1e
Fixed
c9d24a205fd508b9999fcab6aca4c590490a12cf
Fixed
ae20a8a4de06a289d40b0a0633d8d573f1fcb049
Fixed
201e05aa531eba0dfe2ee05b4e178f6ffa12c8b1
Fixed
22666ba1420164753d7b0f5a841986b25ace5435

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74548.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74548.json"