CVE-2026-74255
Last modified
CVE-2026-74255 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in tipc_l2_send_msg() Syzbot reported a slab-use-after-free in ipvlan_hard_header() when called from tipc_l2_send_msg(). The root cause is that tipc_disable_l2_media() calls synchronize_net() while b->media_ptr is still valid. This allows concurrent RCU readers to obtain the device pointer after synchronize_net() has finished. The pointer is cleared later in bearer_disable(), but without any subsequent synchronization, allowing the device to be freed while still in use by readers. Fix this by clearing b->media_ptr in tipc_disable_l2_media() before calling synchronize_net(). This is safe to do now because the call order in bearer_disable() was reversed in 0d051bf93c06 ("tipc: make bearer packet filtering generic") to call tipc_node_delete_links() (which needs the pointer) before disable_media(). https: //lore.kernel.org/netdev/6a2c1007.428ffe26.258b27.015d.GAE@google.com/T/#u. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in tipc_l2_send_msg() Syzbot reported a slab-use-after-free in ipvlan_hard_header() when called from tipc_l2_send_msg(). The root cause is that tipc_disable_l2_media() calls synchronize_net() while b->media_ptr is still valid. This allows concurrent RCU readers to obtain the device pointer after synchronize_net() has finished. The pointer is cleared later in bearer_disable(), but without any subsequent synchronization, allowing the device to be freed while still in use by readers. Fix this by clearing b->media_ptr in tipc_disable_l2_media() before calling synchronize_net(). This is safe to do now because the call order in bearer_disable() was reversed in 0d051bf93c06 ("tipc: make bearer packet filtering generic") to call tipc_node_delete_links() (which needs the pointer) before disable_media(). https: //lore.kernel.org/netdev/6a2c1007.428ffe26.258b27.015d.GAE@google.com/T/#u
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 282b3a056225b35024246f63feb91d769d714dad, < 609ced2301be1df7e7ed2ef47d1d916674e6ba3b; >= 282b3a056225b35024246f63feb91d769d714dad, < 71aafa16d79b107b33837f60b6cbc7d0cb8c5708; >= 282b3a056225b35024246f63feb91d769d714dad, < f4002f1c669cc02e3763f479fc25ff1dfa9e2420; >= 282b3a056225b35024246f63feb91d769d714dad, < 50ff092633b06382e5091dd5b093ce943d4ac2f9; >= 282b3a056225b35024246f63feb91d769d714dad, < aef12b5ce793dea6b3a97a58fd0f946000ae8945; >= 282b3a056225b35024246f63feb91d769d714dad, < 0d8a12d7143126afdf9fbe2e3d438650dd6603ed; >= 282b3a056225b35024246f63feb91d769d714dad, < 35e0297a93c3c34a3924eeef816c03504e3ab5c5; >= 282b3a056225b35024246f63feb91d769d714dad, < f4c3d89fc986b0da196ddfc6cfe0ea5d5d08bec6 |
| Linux | Linux | 4.4 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-74255?
How severe is CVE-2026-74255?
How do I fix CVE-2026-74255?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7425Insufficient option length validation in the IPv6 Router Adv…6.5
- CVE-2026-74250In OpenStack Ironic before 38.0.1, the autodetect deploy int…6.3
- CVE-2026-74251Joomla Extension - phoca.cz - Unauthenticated SQL injection…9.3
- CVE-2026-74252Joomla Extension - j2commerce.com - Stored XSS in Guest chec…8.6
- CVE-2026-74253Joomla Extension - regularlabs.com - Unauthenticated RCE thr…10
- CVE-2026-74254Joomla Extension - joomlack.fr - SQL injection in Page Build…9.3
- CVE-2026-74256In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-74257In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-74258In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-74259In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-7426Insufficient validation of the prefix length field in IPv6 R…8.1
- CVE-2026-74260In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-74255?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
