CVE-2026-74564

Source
https://cve.org/CVERecord?id=CVE-2026-74564
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74564.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74564
Downstream
Published
2026-08-15T12:28:06Z
Modified
2026-08-21T03:30:12Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH

The XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the dsthash_ent structure which represents an entry in the hashtable. There is a union area which uses a different layout to express the rate match mode.

Update .checkentry path to validate the XT_HASHLIMIT_RATE_MATCH mode flag is requested by two or more different rules that refer to the same hashtable. Otherwise, uninitialized access to the burst field in the union is possible.

Reject the use of the XT_HASHLIMIT_RATE_MATCH mode flag if set on by revision less than 3 too.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74564.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bea74641e3786d51dcf1175527cc1781420961c9
Fixed
402befce5854c195058cf4bab7c78ca286068a26
Fixed
dee686b5e7f21180538ff719867702f411c8eb5c
Fixed
f76ab783e7d8d33e33dd7dfa697297f70d57b0e8
Fixed
24683fea1f06bd3bd2707b99460e859bc6464c22
Fixed
32ec8d4aba2cf22e12bdc28df8c4bd833c195fc0
Fixed
d186f77d18bdfb252d401ff992ca3001a6a65a0f
Fixed
06a76334243ccd875a981aa8bb46c0f931ef1e3b
Fixed
305b63e1402267459fdabb183af4527f6799eebf

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74564.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.14.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74564.json"