CVE-2026-74736

Source
https://cve.org/CVERecord?id=CVE-2026-74736
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74736.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74736
Downstream
Published
2026-08-26T14:36:49.950Z
Modified
2026-08-28T03:47:18.086348867Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net/sched: cls_bpf: reject dev-bound programs bound to a different device
Details

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_bpf: reject dev-bound programs bound to a different device

clsbpfprogfromefd() obtained a SCHEDCLS program via bpfproggettypedev() but never verified that a device-bound (offloaded) program's bound netdev matches the TC netdev the classifier is being attached to. This let a program loaded with progifindex for device A be attached via clsbpf + skipsw to device B; deleting device A then destroyed the program's offload state while it was still attached to device B, triggering a netdevsim WARN (panic with paniconwarn=1).

Mirror the XDP attach path (net/core/dev.c) and reject the attach with -EINVAL when a dev-bound program's bound device does not match the target device.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74736.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2b3486bc2d237ec345b3942b7be5deabf8c8fed1
Fixed
ec5a552f4b2d841c6c021752450716e1a9676661
Fixed
daf546ab5763ce6a18280cb4db060e836c515301
Fixed
adb3e7c26a51a10d94a241c6de7a81a2863dcacf
Fixed
5685bbbd3cbfbeb0de96a1d275a5ca073dfebb5e
Fixed
120977e2c096deea4e866e4273be9220b957c29e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74736.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.3.0
Fixed
6.6.153
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.105
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.46
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74736.json"