Use-after-free in Linux kernel - CVE-2026-74583

 

Use-after-free in Linux kernel - CVE-2026-74583

Published: August 24, 2026


Vulnerability identifier: #VU144984
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74583
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the route4 fastmap cache in the cls_route classifier when classifying packets concurrently with filter deletion or modification. A local user can trigger concurrent packet classification and filter updates to cause a denial of service.

The issue is caused by a race in which an in-flight reader can republish a stale filter pointer into the fastmap after the entry has been reset and before the deferred free completes.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74583

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins