CVE-2026-74705 (GCVE-0-2026-74705)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-25 05:41
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP header before ensuring the tunnel header is in the skb head. If the pull reallocates skb->head, the saved UDP header pointer is no longer valid. Get the UDP header after the pull to avoid a potential use-after-free.
Impacted products
Vendor Product Version
Linux Linux Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7
Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7
Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7
Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7
Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7
Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7
Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7
Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/ipv4/udp_offload.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "6a733a38b983d8c2e222f13968209010cf44de87",
              "status": "affected",
              "version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
              "versionType": "git"
            },
            {
              "lessThan": "19d89b13a43640b2da2f277ee462d919d988cb6f",
              "status": "affected",
              "version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
              "versionType": "git"
            },
            {
              "lessThan": "b3df61bb745eb5201eac22679a2839d4ccbf3442",
              "status": "affected",
              "version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
              "versionType": "git"
            },
            {
              "lessThan": "1ae134c012e10384cdac420b5cc6e0615cde0b55",
              "status": "affected",
              "version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
              "versionType": "git"
            },
            {
              "lessThan": "5161e67c561c4f28a5d9335a6e859b02511de92b",
              "status": "affected",
              "version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
              "versionType": "git"
            },
            {
              "lessThan": "64d322c288577793eedd352b96ef75234ed380fe",
              "status": "affected",
              "version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
              "versionType": "git"
            },
            {
              "lessThan": "588d4a6795d99d080f74ef0b5f391ea8c453ae5d",
              "status": "affected",
              "version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
              "versionType": "git"
            },
            {
              "lessThan": "d0f86fb36eb260abd10007b62c9dcc1028e03e61",
              "status": "affected",
              "version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/ipv4/udp_offload.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.6"
            },
            {
              "lessThan": "4.6",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.152",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.104",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.45",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.9",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.265",
                  "versionStartIncluding": "4.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.216",
                  "versionStartIncluding": "4.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.183",
                  "versionStartIncluding": "4.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.152",
                  "versionStartIncluding": "4.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.104",
                  "versionStartIncluding": "4.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.45",
                  "versionStartIncluding": "4.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.9",
                  "versionStartIncluding": "4.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "4.6",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nudp: fix potential use-after-free in tunnel segmentation\n\n__skb_udp_tunnel_segment() gets the UDP header before ensuring the\ntunnel header is in the skb head. If the pull reallocates skb-\u003ehead,\nthe saved UDP header pointer is no longer valid.\n\nGet the UDP header after the pull to avoid a potential use-after-free."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 10,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - Remote peers reach __skb_udp_tunnel_segment on egress when GRO-coalesced VXLAN/Geneve/FOU GSO superpackets are forwarded or re-encapsulated through dev_queue_xmit, and malicious virtio-net/cloud tenants can inject VIRTIO_NET_HDR_GSO_UDP_TUNNEL frames the host later segments on physical or overlay NICs.\nAC:L - Triggering is deterministic once a GSO UDP-tunnel skb has tunnel headers beyond skb_headlen so pskb_may_pull reallocates skb-\u003ehead; attackers control that layout via fragmented or GRO-built outer/encap headers and can repeat crafted sends until segmentation dereferences the stale UDP pointer.\nPR:N - No host authentication or credentials are required to send UDP tunnel traffic to listening overlay ports on cloud/DC nodes, and co-resident virtio-net guests or tenant VMs can emit GSO UDP-tunnel frames into the host datapath without CAP_NET_ADMIN on the victim host.\nUI:N - Exploitation needs only crafted encapsulated GSO traffic into an already-running overlay, bridge, IPVS, OVS, or virtio forwarding path; no victim file open, mount, link click, or other interactive action beyond normal network or VM I/O.\nS:C - In cloud/Kubernetes and virtio-net multitenant deployments, remote or guest/tenant senders can corrupt hypervisor kernel heap during host-side UDP-tunnel GSO segmentation on egress, crossing the VM/container-to-host security boundary rather than staying within the attacker\u0027s own namespace.\nC:H - After pskb_may_pull reallocates skb-\u003ehead, the pre-pull udp_hdr pointer is stale yet uh-\u003elen and uh-\u003echeck are read for checksum adjustment, yielding a classic heap use-after-free read primitive that can disclose kernel memory and support further exploitation.\nI:H - UAF on the UDP header allows attacker-influenced heap reuse and corruption of header fields and checksum state during tunnel GSO segmentation, providing a write/control primitive suitable for kernel code execution rather than a benign checksum miscalculation.\nA:H - Dereferencing the freed UDP header during GSO segmentation can immediately oops or panic the kernel, and repeated exploitation attempts against this UAF commonly crash or hang the host even when full control is not achieved."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-25T05:41:48.767Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6a733a38b983d8c2e222f13968209010cf44de87"
        },
        {
          "url": "https://git.kernel.org/stable/c/19d89b13a43640b2da2f277ee462d919d988cb6f"
        },
        {
          "url": "https://git.kernel.org/stable/c/b3df61bb745eb5201eac22679a2839d4ccbf3442"
        },
        {
          "url": "https://git.kernel.org/stable/c/1ae134c012e10384cdac420b5cc6e0615cde0b55"
        },
        {
          "url": "https://git.kernel.org/stable/c/5161e67c561c4f28a5d9335a6e859b02511de92b"
        },
        {
          "url": "https://git.kernel.org/stable/c/64d322c288577793eedd352b96ef75234ed380fe"
        },
        {
          "url": "https://git.kernel.org/stable/c/588d4a6795d99d080f74ef0b5f391ea8c453ae5d"
        },
        {
          "url": "https://git.kernel.org/stable/c/d0f86fb36eb260abd10007b62c9dcc1028e03e61"
        }
      ],
      "title": "udp: fix potential use-after-free in tunnel segmentation",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-74705",
    "datePublished": "2026-08-22T15:33:04.110Z",
    "dateReserved": "2026-08-15T05:44:03.927Z",
    "dateUpdated": "2026-08-25T05:41:48.767Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…