Use of uninitialized resource in Linux kernel - CVE-2026-74564
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to uninitialized memory access in xt_hashlimit when processing hashlimit rule configuration with inconsistent XT_HASHLIMIT_RATE_MATCH usage for the same hashtable. A local user can create specially crafted netfilter rules to cause a denial of service.
The issue arises when different rules referring to the same hashtable use conflicting rate match semantics, and revision values less than 3 are also affected when the flag is used.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74564
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/06a76334243ccd875a981aa8bb46c0f931ef1e3b
- https://git.kernel.org/stable/c/24683fea1f06bd3bd2707b99460e859bc6464c22
- https://git.kernel.org/stable/c/305b63e1402267459fdabb183af4527f6799eebf
- https://git.kernel.org/stable/c/32ec8d4aba2cf22e12bdc28df8c4bd833c195fc0
- https://git.kernel.org/stable/c/d186f77d18bdfb252d401ff992ca3001a6a65a0f