SB20260816160 - Use of uninitialized resource in Linux kernel netfilter
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of uninitialized resource (CVE-ID: CVE-2026-74564)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to uninitialized memory access in xt_hashlimit when processing hashlimit rule configuration with inconsistent XT_HASHLIMIT_RATE_MATCH usage for the same hashtable. A local user can create specially crafted netfilter rules to cause a denial of service.
The issue arises when different rules referring to the same hashtable use conflicting rate match semantics, and revision values less than 3 are also affected when the flag is used.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/06a76334243ccd875a981aa8bb46c0f931ef1e3b
- https://git.kernel.org/stable/c/24683fea1f06bd3bd2707b99460e859bc6464c22
- https://git.kernel.org/stable/c/305b63e1402267459fdabb183af4527f6799eebf
- https://git.kernel.org/stable/c/32ec8d4aba2cf22e12bdc28df8c4bd833c195fc0
- https://git.kernel.org/stable/c/d186f77d18bdfb252d401ff992ca3001a6a65a0f