SB20260816246 - Use-after-free in Linux kernel openvswitch
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-74465)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the openvswitch meter handling code when processing crafted netlink requests through the uAPI. A local user can trigger meter attach failure conditions and concurrently access the freed meter to cause a denial of service.
Exploitation is possible with a custom application using the uAPI, while the issue is not triggered in the typical ovs-vswitchd usage pattern described in the advisory.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0310d1fa7f9debd0d89629e9f14c7975a47eaa9a
- https://git.kernel.org/stable/c/431a295d93f76fbdb6a7cfce92a9e3dfee1e5d61
- https://git.kernel.org/stable/c/4d03e5fa3fbb1df15258a1eb3d6963f0d65659b3
- https://git.kernel.org/stable/c/90623c9499627803ef3f04fa25a3199402d4fb95
- https://git.kernel.org/stable/c/a58a2b0ce354df531ebc71fc870058c2feb59f6b