CVE-2026-74406
Published: August 18, 2026Last modified: August 18, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). udp_tunnel_sock_release() could set sk->sk_user_data to NULL while vxlan_gro_prepare_receive() is running. Let's check if rcu_dereference_sk_user_data() is NULL after skb_gro_remcsum_init().
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 9.8 |
| Attack Vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity impact | HIGH |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Fixed (6.1.182-r0) |
| 25 LTS | linux-lts | Fixed (6.12.103-r0) | |
| Stream | linux-lts | Fixed (6.18.43-r0) |
References
- https://git.kernel.org/stable/c/08f40c0d23c67c3aa4224c3311e134999c721fb4
- https://git.kernel.org/stable/c/30a45c0bffdd62350261e2f2689fdba426a33578
- https://git.kernel.org/stable/c/4a8cde6f7281ea2c4c290f9ad9923b3631defceb
- https://git.kernel.org/stable/c/9c58c729d32e7cea5772cc44929c6cd61e5a31cd
- https://git.kernel.org/stable/c/ef44dac2a37f86eeae6b88ed10a6d60b35387dfd
- https://git.kernel.org/stable/c/f79c80f173fda9545b220c1f094b65fc06c252d0