CVE-2026-74746

Source
https://cve.org/CVERecord?id=CVE-2026-74746
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74746.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74746
Downstream
Published
2026-08-26T14:36:55.963Z
Modified
2026-08-28T03:47:13.048452325Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
netfilter: flowtable: publish GC-visible tuple last
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: publish GC-visible tuple last

nfflowtableiterate() only treats original-direction tuple nodes as owning entries. Publishing the original node first lets GC observe and free a flow while flowoffload_add() is still inserting the reply node. Publish the reply node first and the original node last so GC never sees a partially installed flow.

KASAN can trigger slab-use-after-free read and write reports in the flowtable/rhashtable path (rhtdeferredworker, jhash, flowoffloaddel, flowoffloadlookup, etc.).

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74746.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ac2a66665e231847cab11b8c8e844ce43207dd2e
Fixed
0a00254585827f1695aa2700114af622ea754cfa
Fixed
be345dcbddb4643a54252b954af974b16eda8f91
Fixed
211ee5d998d92a7d548811939c65942d06c146e4
Fixed
d37917e7bebe078f3c17e47fd6fc1c9f6e8497b2
Fixed
972fdf7c4f5c282a239c88fea614b056c33dc025
Fixed
d9d3050a70efe217e73a0751e55fdae6a7092620
Fixed
d16b71231e65cb05daea2b45701fcf09cef041e7
Fixed
2014ac62df9d45bb9a004a043e85df7be09ed780

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74746.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.16.0
Fixed
5.10.266
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.217
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.184
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.153
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.105
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.46
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74746.json"