Use-after-free in Linux kernel - CVE-2026-74746
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a use-after-free in the netfilter flowtable subsystem when inserting flow tuple nodes into the rhashtable. A remote attacker can trigger garbage collection to observe a partially installed flow to execute arbitrary code.
KASAN reported read and write access to freed slab memory in the flowtable and rhashtable path.
Affected software
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel (Red Hat package)
How to mitigate CVE-2026-74746
kernel (Red Hat package) - update to 5.14.0-427.153.1.el9_4
External References
- https://git.kernel.org/stable/c/0a00254585827f1695aa2700114af622ea754cfa
- https://git.kernel.org/stable/c/2014ac62df9d45bb9a004a043e85df7be09ed780
- https://git.kernel.org/stable/c/211ee5d998d92a7d548811939c65942d06c146e4
- https://git.kernel.org/stable/c/972fdf7c4f5c282a239c88fea614b056c33dc025
- https://git.kernel.org/stable/c/be345dcbddb4643a54252b954af974b16eda8f91
- https://git.kernel.org/stable/c/d16b71231e65cb05daea2b45701fcf09cef041e7
- https://git.kernel.org/stable/c/d37917e7bebe078f3c17e47fd6fc1c9f6e8497b2
- https://git.kernel.org/stable/c/d9d3050a70efe217e73a0751e55fdae6a7092620