CVE-2026-74583Patch

LOWCVSS 7.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_route: fix fastmap use-after-free on filter The route4 classifier maintains a 16-slot fastmap cache that stores raw struct route4_filter pointers indexed by (id, iif). The reader (route4_classify) populates this cache via route4_set_fastmap() for every classified packet that hits a filter. The writer (route4_delete, route4_change) clears the cache via route4_reset_fastmap() before RCU-deferred kfree of the filter. This creates a UAF race: 1. Reader walks the RCU-protected bucket chain, finds filter f 2. Writer unlinks f, calls route4_reset_fastmap(), then tcf_queue_work() 3. Reader calls route4_set_fastmap() and writes f into the cache *after* the writer's reset, caching a pointer about to be freed 4. After the RCU grace period, kfree(f) executes 5. Next classified packet on the same (id, iif) tuple hits the stale fastmap entry and reads f->res from freed memory Reproduced with an mdelay(100) accelerator in route4_set_fastmap() and a concurrent add/delete stress test (provided by both zdi and Santosh). Both triggered KASAN slab-use-after-free reports in the route4 fastmap paths. Fix: Introduce a per-filter boolean dying flag to suppress stale fastmap republishing by in-flight readers.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-21: 3Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-21: 208-21
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Linux Kernel (CVE-2026-74583) https://vuldb.com/vuln/394149

    Post summary

    The post simply announces that the severity of a new Linux kernel CVE (CVE‑2026‑74583) has increased, pointing to a vulnerability database entry.

    00010140
    2.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-74583 In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_route: fix fastmap use-after-free on filter The route4 classifier maintains a 16-… https://www.cve.org/CVERecord?id=CVE-2026-74583 ----- Traducción: CVE-2026-74583 En … http://infoflow.cloud`

    Post summary

    The post announces that CVE-2026-74583, a use‑after‑free in the Linux kernel’s cls_route net/sched filter, has been fixed, but it provides no PoC, exploit code, or detailed patch information.

    0000030
    102 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-74583 In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_route: fix fastmap use-after-free on filter The route4 classifier maintains a 16-… https://www.cve.org/CVERecord?id=CVE-2026-74583

    Post summary

    CVE‑2026‑74583, a use‑after‑free bug in the Linux kernel’s cls_route module, has been fixed. A patch is available and the CVE record confirms the remediation.

    00000959
    58.0K followersView on X

Explore more