Use-after-free in Linux kernel - CVE-2026-74565

 

Use-after-free in Linux kernel - CVE-2026-74565

Published: August 16, 2026


Vulnerability identifier: #VU143196
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74565
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to use-after-free in nft_object lookup handling in nf_tables when accessing objects during net namespace event processing. A local user can trigger object lookup and destruction across tables to cause a denial of service or execute arbitrary code.

The issue arises because a global object name rhltable could expose objects being dismantled from the lookup path by another existing network namespace.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74565

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins