SB20260824207 - Use-after-free in Linux kernel net
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-74630)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to use-after-free in in6_dev_get() and inet6_dev handling when processing IPv6 device state during concurrent device teardown. A local user can trigger network operations that race with device teardown to cause a denial of service or execute arbitrary code.
The issue arises from invalid reference acquisition after the object reference count has already reached zero, and the freed object may be accessed after the RCU read-side section ends.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0e243671bc7b8eaf00f83dd2f4367436dc0cff98
- https://git.kernel.org/stable/c/145812b678de9f3b59780173be3c0d22ed60dd93
- https://git.kernel.org/stable/c/14e812ab41df0cac033479da835ec9a5de633404
- https://git.kernel.org/stable/c/1c206d461c680c3151daa3c89fc26eaf5bf98a7f
- https://git.kernel.org/stable/c/680fbd7942185448eadb990a3d10a53eb946b702
- https://git.kernel.org/stable/c/785d908f8d21c8bc78b6fb2c2932ab662bf6918a
- https://git.kernel.org/stable/c/aedcfefdb5b7ed7f8a6196a3e68a25bdbe51d2f8
- https://git.kernel.org/stable/c/cc5bd568f9b7683e60841b6fd02c10d64535bd6e