Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-74726— bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: bonding(网络绑定):alb 模式 – 在 中于持有 RTNL 锁期间重新检查 状态 函数在读取 时使用的是 RCU(Read-Copy-Update)机制,随后释放 RCU 锁,并通过 获取 RTNL(路由网络锁),以撤销其对活动从属接口(active slave)之前设置的混杂模式(promiscuity)。然而,在该时间窗口内,当前的活动从属接口可能在持有 RTNL 锁的情况下发生变化(路径: → → )。此变更过程已撤销混杂模式并清除了 标志。但监控函数仍

AI Predicted 5.5 Difficulty: Moderate EPSS 0.22% · P13

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux d0e81b7e2246a41d068ecaf15aac9de570816d63< f7668762bf5fd6db9397de5c0514407489d9d815 affected
d0e81b7e2246a41d068ecaf15aac9de570816d63< 09add8d5cfa9c46828f51eaad162c36e86366b71 affected
d0e81b7e2246a41d068ecaf15aac9de570816d63< b82f51681a7a88c7d3c865e817a3340d42b5fa2a affected
d0e81b7e2246a41d068ecaf15aac9de570816d63< dd148539fb4741d01c06b7d2c8bd84b01920756c affected
d0e81b7e2246a41d068ecaf15aac9de570816d63< dccec0227ed8d9e36936d66e256b957dc2858468 affected
d0e81b7e2246a41d068ecaf15aac9de570816d63< 2faf75a8a06504071b4c0aea7e45a9cc49a4e187 affected
d0e81b7e2246a41d068ecaf15aac9de570816d63< 257c4a3a34d8f51efb00f35375a0c6ce3c8f6ce2 affected
d0e81b7e2246a41d068ecaf15aac9de570816d63< 683c6ba6e58e6ed1037831ea97dd58d9c0e76b8d affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-74726

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor bond_alb_monitor() reads primary_is_promisc under RCU, then drops RCU and takes RTNL via rtnl_trylock() before undoing the promiscuity it set on the active slave. In that window the active slave can change under RTNL (RTM_DELLINK -> __bond_release_one() -> bond_alb_handle_active_change()), which already drops the promiscuity and clears primary_is_promisc. The monitor still acts on the stale decision: if the slave was removed with no failover, curr_active_slave is now NULL and the deref faults; if it failed over, the stale dev_set_promiscuity(-1) underflows the new slave's promiscuity counter and pins it in IFF_PROMISC. Oops: general protection fault, probably for non-canonical address ... KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] Workqueue: b42 bond_alb_monitor RIP: 0010:bond_alb_monitor (drivers/net/bonding/bond_alb.c:1600) process_one_work (kernel/workqueue.c:3322) worker_thread (kernel/workqueue.c:3486) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:158) Kernel panic - not syncing: Fatal exception Re-check primary_is_promisc (and curr_active_slave) after taking RTNL so the monitor only undoes an increment it still owns. The other bonding monitors already re-read state under RTNL in their commit phase (bond_miimon_commit/bond_ab_arp_commit); bond_alb_monitor() was the only one acting on the pre-trylock decision.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux d0e81b7e2246a41d068ecaf15aac9de570816d63 ~ f7668762bf5fd6db9397de5c0514407489d9d815 -
Linux Linux 2.6.24 -

II. Public POCs for CVE-2026-74726

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-74726

登录查看更多情报信息。

Patches & Fixes for CVE-2026-74726 (8)

Same Patch Batch · Linux · 2026-08-22 · 150 CVEs total

CVE-2026-74638 drm/v3d: Serialize the scheduler timeout handlers
CVE-2026-74621 net/sched: act_ct: fix sk_buff leak when the header checks reject a packet
CVE-2026-74622 net: atlantic: free RX pages of consumed but not refilled buffers
CVE-2026-74623 net: atlantic: free stranded TX buffers on ring deinit
CVE-2026-74624 netfilter: nf_conntrack: defer invalid log until after unlock
CVE-2026-74625 netfilter: bridge: release template ct on non-IP path
CVE-2026-74627 net: devmem: prevent net-iov / page mixing
CVE-2026-74626 NTB: ntb_netdev: Preserve RX queue depth on allocation failure
CVE-2026-74628 net/x25: fix use-after-free of the socket by its timers
CVE-2026-74629 net/dibs: Correct freeing of dmb_clientid_arr
CVE-2026-74631 net: smc: fix splice entry lifetime imbalance in smc_rx_splice
CVE-2026-74630 ipv6: prevent in6_dev_get() from resurrecting inet6_dev
CVE-2026-74632 mm/huge_memory: fix huge_zero_pfn race
CVE-2026-74633 tracing: Fix NULL pointer dereference in module event cache removal
CVE-2026-74634 ring-buffer: Prevent subbuf order change when resizing is disabled
CVE-2026-74635 fbdev: bitblit: bound-check glyph index in bit_cursor()
CVE-2026-74636 tracing: Fix race between update_event_fields and, event_define_fields
CVE-2026-74637 perf/core: Fix group leader use-after-free after sibling detach
CVE-2026-74639 ALSA: us144mkii: re-anchor capture URBs on resubmission
CVE-2026-74650 staging: rtl8723bs: fix OOB read in WMM_param_handler()

Showing top 20 of 150 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-74726

No comments yet


Leave a comment