Use-after-free in Linux kernel - CVE-2026-74746

 

Use-after-free in Linux kernel - CVE-2026-74746

Published: August 27, 2026


Vulnerability identifier: #VU145979
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74746
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a use-after-free in the netfilter flowtable subsystem when inserting flow tuple nodes into the rhashtable. A remote attacker can trigger garbage collection to observe a partially installed flow to execute arbitrary code.

KASAN reported read and write access to freed slab memory in the flowtable and rhashtable path.


Affected software

Linux kernel
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel (Red Hat package)

How to mitigate CVE-2026-74746

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
kernel (Red Hat package) - update to 5.14.0-427.153.1.el9_4

External References

Related Security Bulletins