Use-after-free in Linux kernel - CVE-2026-74744
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a use-after-free in the ipvlan network device component when handling packet header and tailroom requirements inherited from the underlying physical device. A remote attacker can trigger packet processing that causes insufficient headroom or tailroom reservation to execute arbitrary code.
The issue can occur when the underlying physical or stacked lower device requires extra headroom or tailroom for headers or trailers.
Affected software
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python2-perf
python2-perf-debuginfo
python3-perf
python3-perf-debuginfo
How to mitigate CVE-2026-74744
kernel - update to 4.19.90-2609.3.0.0391
bpftool - update to 4.19.90-2609.3.0.0391
bpftool-debuginfo - update to 4.19.90-2609.3.0.0391
kernel-debuginfo - update to 4.19.90-2609.3.0.0391
kernel-debugsource - update to 4.19.90-2609.3.0.0391
kernel-devel - update to 4.19.90-2609.3.0.0391
kernel-source - update to 4.19.90-2609.3.0.0391
kernel-tools - update to 4.19.90-2609.3.0.0391
kernel-tools-debuginfo - update to 4.19.90-2609.3.0.0391
kernel-tools-devel - update to 4.19.90-2609.3.0.0391
perf - update to 4.19.90-2609.3.0.0391
perf-debuginfo - update to 4.19.90-2609.3.0.0391
python2-perf - update to 4.19.90-2609.3.0.0391
python2-perf-debuginfo - update to 4.19.90-2609.3.0.0391
python3-perf - update to 4.19.90-2609.3.0.0391
python3-perf-debuginfo - update to 4.19.90-2609.3.0.0391
External References
- https://git.kernel.org/stable/c/5c2ca77212eb38559b0353b8363b7a84f4b019dd
- https://git.kernel.org/stable/c/5f33188457bbcc1b11ca87084037963c516ed3d9
- https://git.kernel.org/stable/c/af602c4d0ee548da18e2409b4b4da1079625a372
- https://git.kernel.org/stable/c/c0fbe31f6b20ade0465130685859faa5c86fda59
- https://git.kernel.org/stable/c/e16e960d55a40d36bd7c2494cc005e757dc9a1ef
- https://git.kernel.org/stable/c/f3c17ff65f54781cde696e16a6c577615ed735aa