Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-74746— netfilter: flowtable: publish GC-visible tuple last

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux 内核中已修复以下漏洞: netfilter:flowtable:最后发布 GC 可见的五元组 仅将原始方向的五元组节点视为拥有该条目的节点。如果先发布原始节点,垃圾回收器(GC)可能会在 仍在插入回复节点时,观察到并释放该流表项。因此,应先发布回复节点,最后发布原始节点,以确保 GC 不会看到未完全安装完成的流表项。 KASAN 可在 flowtable/rhashtable 路径(如 、 、 、 等)中触发 slab-use-after-free 的读取和写入报告。

CVSS 9.8 · Critical

Possible ATT&CK Techniques 1 AI

T1027 · Obfuscated Files or Information

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux ac2a66665e231847cab11b8c8e844ce43207dd2e< 0a00254585827f1695aa2700114af622ea754cfa affected
ac2a66665e231847cab11b8c8e844ce43207dd2e< be345dcbddb4643a54252b954af974b16eda8f91 affected
ac2a66665e231847cab11b8c8e844ce43207dd2e< 211ee5d998d92a7d548811939c65942d06c146e4 affected
ac2a66665e231847cab11b8c8e844ce43207dd2e< d37917e7bebe078f3c17e47fd6fc1c9f6e8497b2 affected
ac2a66665e231847cab11b8c8e844ce43207dd2e< 972fdf7c4f5c282a239c88fea614b056c33dc025 affected
ac2a66665e231847cab11b8c8e844ce43207dd2e< d9d3050a70efe217e73a0751e55fdae6a7092620 affected
ac2a66665e231847cab11b8c8e844ce43207dd2e< d16b71231e65cb05daea2b45701fcf09cef041e7 affected
ac2a66665e231847cab11b8c8e844ce43207dd2e< 2014ac62df9d45bb9a004a043e85df7be09ed780 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-74746

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netfilter: flowtable: publish GC-visible tuple last
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() only treats original-direction tuple nodes as owning entries. Publishing the original node first lets GC observe and free a flow while flow_offload_add() is still inserting the reply node. Publish the reply node first and the original node last so GC never sees a partially installed flow. KASAN can trigger slab-use-after-free read and write reports in the flowtable/rhashtable path (rht_deferred_worker, jhash, flow_offload_del, flow_offload_lookup, etc.).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux ac2a66665e231847cab11b8c8e844ce43207dd2e ~ 0a00254585827f1695aa2700114af622ea754cfa -
Linux Linux 4.16 -

II. Public POCs for CVE-2026-74746

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-74746

登录查看更多情报信息。

Patches & Fixes for CVE-2026-74746 (8)

Same Patch Batch · Linux · 2026-08-26 · 92 CVEs total

CVE-2026-74752 9.8 CRITICAL sctp: validate cookie AUTH state before use
CVE-2026-80589 9.8 CRITICAL block: stop the timeout timer when releasing a never added disk
CVE-2026-74737 9.8 CRITICAL net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
CVE-2026-80557 9.8 CRITICAL libceph: fix OOB read in decode_watchers() via missing bounds check
CVE-2026-80587 9.8 CRITICAL mptcp: avoid combining some incoming suboptions
CVE-2026-80528 9.8 CRITICAL ceph: avoid fs reclaim while using current->journal_info
CVE-2026-80561 9.8 CRITICAL libceph: fix multiple unsafe decodes in decode_locker()
CVE-2026-74743 9.8 CRITICAL macvlan: inherit needed_headroom and needed_tailroom from lowerdev
CVE-2026-74744 9.8 CRITICAL ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
CVE-2026-80558 9.8 CRITICAL libceph: Avoid using invalid osd indices from primary_temp
CVE-2026-80519 9.8 CRITICAL ovpn: finish crypto callback cleanup before peer release
CVE-2026-80586 9.8 CRITICAL mptcp: options: reset DSS fields in case of unexpected size
CVE-2026-74751 9.4 CRITICAL riscv: lib: Fix ZBB strnlen reading past count boundary
CVE-2026-80585 9.4 CRITICAL mptcp: fastopen: only mark MPTFO subflows with SYN data
CVE-2026-80554 9.3 CRITICAL s390/vfio_ccw: Limit the number of channel program segments
CVE-2026-80551 9.3 CRITICAL s390/vfio_ccw: Ensure first IDAW remains constant
CVE-2026-80576 8.8 HIGH drm/amdgpu: reject oversized IBs with per-ring packet limits
CVE-2026-80553 8.8 HIGH s390/vfio_ccw: Cancel existing workqueues
CVE-2026-80547 8.8 HIGH s390/vfio_ccw: Implement a crw lock
CVE-2026-80552 8.8 HIGH s390/vfio_ccw: Ensure index for read/write regions are within range

Showing top 20 of 92 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-74746

No comments yet


Leave a comment