CVE-2026-74695

Source
https://cve.org/CVERecord?id=CVE-2026-74695
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74695.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74695
Downstream
AZL (1)
BELL (1)
DEBIAN (1)
openSUSE (1)
SUSE (14)
UBUNTU (1)
Related
Published
2026-08-22T15:32:57Z
Modified
2026-10-08T02:51:56Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()

Incoming skbs passing through netfilter flowtable offload hooks (or XFRM offload path) might already carry a ref-counted dst_entry assigned during earlier RX or routing steps.

Calling skb_dst_set_noref() when skb already holds a ref-counted dst overwrites skb->_skb_refdst, leaking the previous dst_entry reference count and triggering a DEBUG_NET_WARN_ON_ONCE assertion in skb_dst_check_unset():

WARNING: at skb_dst_check_unset include/linux/skbuff.h:1170 WARNING: at skb_dst_set_noref include/linux/skbuff.h:1234 WARNING: at nf_flow_offload_ip_hook+0xf6c/0x2b60 net/netfilter/nf_flow_table_ip.c:864

Drop any existing dst_entry reference with skb_dst_drop(skb) before setting the non-referenced flowtable destination.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74695.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2a79fd3908acd88e6cb0e620c314d7b1fee56a02
Fixed
12afa450a6a6c0cce2c42b7545a9958f62d8a00c
Fixed
538e67e8c7889cf5f93951f5309d1bcb41f86036
Fixed
8aecf0bbcc72605592134c917c222207d8f63ab0
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4.16.15
Fixed
4.17
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4.17.1
Fixed
4.18
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b4b1adf2e66ecc7125c4117e7aad9ff61e2cfd27
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
209dedf806d31095968f54323dbe62525b077b33

Affected versions

v4.*
v4.16.15
v4.16.16
v4.16.17
v4.16.18
v4.17.1
v4.17.10
v4.17.11
v4.17.12
v4.17.13
v4.17.14
v4.17.15
v4.17.16
v4.17.17
v4.17.18
v4.17.19
v4.17.2
v4.17.3
v4.17.4
v4.17.5
v4.17.6
v4.17.7
v4.17.8
v4.17.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74695.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.18.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74695.json"