Use-after-free in Linux kernel - CVE-2026-74615
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a use-after-free in the vxlan ageing timer handling in drivers/net/vxlan/vxlan_core.c when changing link ageing settings on a device that is down. A remote user can create and delete a VXLAN device in a new user and network namespace to cause a denial of service.
The affected operations are network-namespace scoped.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74615
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/26c179d47403d2f919ee914cc02c31d896b59fee
- https://git.kernel.org/stable/c/46bb297ad77680e009244f067f27d51cf5b8c7cf
- https://git.kernel.org/stable/c/619dd29045e439d0b0f8c6d4fec1af447a050680
- https://git.kernel.org/stable/c/6b095e99b9e67ea31f0c4b00260e010898253519
- https://git.kernel.org/stable/c/6b4119af544996a545cf84b16f1dbce829ba0de8
- https://git.kernel.org/stable/c/9dc561f0522c35bdd66e0646a748814a138ec4ca
- https://git.kernel.org/stable/c/b37971686ec59fb027fa4910ba16805e68fddb97
- https://git.kernel.org/stable/c/be44d79d14d7f9ae7c8ffb7272142005341b5123