Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-74720— bpf: Preserve pointer state for commuted arithmetic

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: bpf: 保留交换顺序算术运算中的指针状态 当 函数处理 运算时,目标寄存器会从源指针继承指针状态。仅复制部分字段的做法较为脆弱,因为指针的出处(provenance)由多个 字段共同追踪。 本修复使用调用者提供的临时偏移寄存器来保存标量操作数,同时将目标寄存器替换为完整的指针状态。这样可以保留 类型指针的栈帧编号,并保持父标识字段的一致性。

CVSS 7.8 · High EPSS 0.22% · P13

Possible ATT&CK Techniques 1 AI

T1564.004 · NTFS File Attributes

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux f4d7e40a5b7157e1329c3c5b10f60d8289fc2941< 86b203aadc2930e0a4f9c6277b5b80ff3664c472 affected
f4d7e40a5b7157e1329c3c5b10f60d8289fc2941< 8109c25e0c41f5f19a1c2380bb49c991a877494e affected
f4d7e40a5b7157e1329c3c5b10f60d8289fc2941< d1959028190a7649b926f5867a58de5fe221b23c affected
f4d7e40a5b7157e1329c3c5b10f60d8289fc2941< 8cb23101a3fcc7432b451ea3d0f14a90711f4acf affected
f4d7e40a5b7157e1329c3c5b10f60d8289fc2941< 29c239f8dbec5ab33a61796724d189bddee6cd4b affected
f4d7e40a5b7157e1329c3c5b10f60d8289fc2941< db6382ed3361bdd8129572a3423956cba1dae829 affected
f4d7e40a5b7157e1329c3c5b10f60d8289fc2941< eaffa1495e4fe6330aeff9f323ea3d48b01f118a affected
f4d7e40a5b7157e1329c3c5b10f60d8289fc2941< a4c6f804b44c5c790269b25e0e61cf4e9f117c86 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-74720

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bpf: Preserve pointer state for commuted arithmetic
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer state for commuted arithmetic When scalar += pointer is handled in adjust_ptr_min_max_vals(), the destination register inherits the pointer state from the source pointer. Copying only selected fields is fragile because pointer provenance is tracked by several bpf_reg_state fields. Use the caller's temporary offset register to preserve the scalar operand while replacing the destination with the full pointer state. This preserves the frame number for PTR_TO_STACK registers and keeps parent identity fields consistent.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 ~ 86b203aadc2930e0a4f9c6277b5b80ff3664c472 -
Linux Linux 4.16 -

II. Public POCs for CVE-2026-74720

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-74720

登录查看更多情报信息。

Patches & Fixes for CVE-2026-74720 (8)

Same Patch Batch · Linux · 2026-08-22 · 150 CVEs total

CVE-2026-74612 10.0 CRITICAL veth: fix skb length accounting after XDP frag adjustment
CVE-2026-74705 10.0 CRITICAL udp: fix potential use-after-free in tunnel segmentation
CVE-2026-74611 9.8 CRITICAL tls: rx: restore msg_iter before TLS 1.3 optimistic retry
CVE-2026-74617 9.8 CRITICAL dibs: initialise dibs->lock in dibs_dev_alloc()
CVE-2026-74628 9.8 CRITICAL net/x25: fix use-after-free of the socket by its timers
CVE-2026-74597 9.8 CRITICAL ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
CVE-2026-74616 9.8 CRITICAL xdp: reject clones that overrun skb_shared_info tailroom
CVE-2026-74591 9.8 CRITICAL mm/filemap: __filemap_add_folio() restore index before retrying
CVE-2026-74688 9.8 CRITICAL sctp: clear control chunk transport if it is being removed
CVE-2026-74587 9.8 CRITICAL sctp: fix use-after-free of cached ASCONF chunk
CVE-2026-74608 9.8 CRITICAL smb: client: Fix use-after-free in cifs_try_adding_channels()
CVE-2026-74723 9.8 CRITICAL btrfs: lzo: reject inline extents without valid headers
CVE-2026-74730 9.8 CRITICAL NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
CVE-2026-74727 9.8 CRITICAL ovpn: skip rehash for peers already removed from by_id
CVE-2026-74586 9.8 CRITICAL sctp: clear new_transport when removing a peer
CVE-2026-74662 9.8 CRITICAL inet: frags: publish queues before arming timer
CVE-2026-74669 9.8 CRITICAL ipvs: clear IPv4 options after rebasing tunnel ICMP errors
CVE-2026-74588 9.8 CRITICAL sctp: keep chunk->transport in step with the list it is queued on
CVE-2026-74712 9.3 CRITICAL vdpa/mlx5: Fix buffer length in create_direct_keys()
CVE-2026-74665 9.1 CRITICAL net: fix skb length accounting after generic XDP frag adjustment

Showing top 20 of 150 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-74720

No comments yet


Leave a comment