Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-74398— ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于ipv6 addrconf模块中addrconf_dad_failure函数状态处理不当,并发删除地址时可能访问已释放的链表项,导致内核崩溃。

CVSS 9.8 · Critical EPSS 0.52% · P42

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux c15b1ccadb323ea50023e8f1cca2954129a62b51< 47b05836705b63dab93d9ac7c69a3a507375ef80 affected
c15b1ccadb323ea50023e8f1cca2954129a62b51< d21be7d051012c6b572fa4e3334443c250216f7b affected
c15b1ccadb323ea50023e8f1cca2954129a62b51< 875c284c0f98b042bb97abad460f63a24c977f88 affected
c15b1ccadb323ea50023e8f1cca2954129a62b51< 8ed0ce9ea58d677d1bac92614ee5f60f8ea57363 affected
c15b1ccadb323ea50023e8f1cca2954129a62b51< 3bdc86d89fd6c6523753fa6f42fcfaf30ee699cb affected
c15b1ccadb323ea50023e8f1cca2954129a62b51< b61af0268e3d1308c466bf0be5dced844eafc1ef affected
c15b1ccadb323ea50023e8f1cca2954129a62b51< e889aa99ad3ed48bb0ddcff6475b17542532d18b affected
c15b1ccadb323ea50023e8f1cca2954129a62b51< 627ac78f2741e2ebd2225e2e953b6964a8a9182f affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-74398

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD addrconf_dad_failure() transitions ifp->state from DAD to POSTDAD via addrconf_dad_end(), which drops ifp->lock on return. The lock is re-acquired after net_info_ratelimited(). A concurrent ipv6_del_addr() can take the lock in that window, set ifp->state to DEAD and run list_del_rcu(&ifp->if_list). addrconf_dad_failure() then overwrites DEAD with ERRDAD at errdad: and schedules a new dad_work. The work calls ipv6_del_addr() again, hitting the already-poisoned list entry: general protection fault: 0000 [#1] SMP NOPTI CPU: 4 PID: 217 Comm: kworker/4:1 Workqueue: ipv6_addrconf addrconf_dad_work RIP: 0010:ipv6_del_addr+0xe9/0x280 RAX: dead000000000122 Call Trace: addrconf_dad_stop+0x113/0x140 addrconf_dad_work+0x28c/0x430 process_one_work+0x1eb/0x3b0 worker_thread+0x4d/0x400 kthread+0x104/0x140 ret_from_fork+0x35/0x40 Fold the addrconf_dad_end() logic into addrconf_dad_failure() under a single ifp->lock critical section. The STABLE_PRIVACY branch temporarily drops ifp->lock around address regeneration, so at lock_errdad: verify the state is still POSTDAD before transitioning to ERRDAD; bail out otherwise to avoid overwriting a state set by another path while the lock was released.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于ipv6 addrconf模块中addrconf_dad_failure函数状态处理不当,并发删除地址时可能访问已释放的链表项,导致内核崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux c15b1ccadb323ea50023e8f1cca2954129a62b51 ~ 47b05836705b63dab93d9ac7c69a3a507375ef80 -
Linux Linux 3.14 -

II. Public POCs for CVE-2026-74398

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-74398

登录查看更多情报信息。

Patches & Fixes for CVE-2026-74398 (8)

Same Patch Batch · Linux · 2026-08-15 · 845 CVEs total

CVE-2026-72421 10.0 CRITICAL ipv4: fib: Don't ignore error route in local/main tables.
CVE-2026-72408 10.0 CRITICAL geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVE-2026-74309 10.0 CRITICAL vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
CVE-2026-72407 10.0 CRITICAL geneve: validate inner network offset in geneve_gro_complete()
CVE-2026-74279 10.0 CRITICAL crypto: cavium/cpt - fix DMA cleanup using wrong loop index
CVE-2026-74475 10.0 CRITICAL vxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-74280 10.0 CRITICAL crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
CVE-2026-72493 9.9 CRITICAL net: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-74361 9.8 CRITICAL nvme: fix FDP fdpcidx bounds check
CVE-2026-74268 9.8 CRITICAL tcp: clear sock_ops cb flags before force-closing a child socket
CVE-2026-72064 9.8 CRITICAL net: mana: Sync page pool RX frags for CPU
CVE-2026-72065 9.8 CRITICAL net: mana: Validate the packet length reported by the NIC
CVE-2026-72069 9.8 CRITICAL locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
CVE-2026-72185 9.8 CRITICAL ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock()
CVE-2026-72249 9.8 CRITICAL netfilter: flowtable: use dst in this direction when pushing IPIP header
CVE-2026-72494 9.8 CRITICAL RDMA/irdma: Replace waitqueue and flag with completion
CVE-2026-72248 9.8 CRITICAL netfilter: flowtable: support IPIP tunnel with direct xmit
CVE-2026-72491 9.8 CRITICAL net/9p: fix race condition on rdma->state in trans_rdma.c
CVE-2026-72251 9.8 CRITICAL netfilter: nf_nat_sip: reload possible stale data pointer
CVE-2026-74480 9.8 CRITICAL net: bridge: stop fast-leave after deleting a port group

Showing top 20 of 845 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-74398

No comments yet


Leave a comment