VDB

CVE-2026-74581

CVE-2026-74581 PUBLISHED CVSS 9.8 CRITICAL

Reported by Linux · Published August 21, 2026

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info. If no later rule supplies a replacement, fib6_rule_lookup() still sees res.rt6 and returns that stale dst to its caller. A suppressing rule can therefore leak a released route back to rt6_lookup(), and the next put hits rcuref_put_slowpath() from dst_release(). Clear res->rt6 when suppressing the route so suppressed lookups fall through to the null dst instead of reusing the released one.

EPSS 0.42% · 34.4th percentile

Risk Scores

CVSS 3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.42%
34.4th percentile

Affected Products

VendorProductVersions
LinuxLinux209d35ee34e25f9668c404350a1c86d914c54ffa, 8ef8a76a340ebdb2c2eea3f6fb0ebbed09a16383, cdef485217d30382f3bf6448c54b4401648fe3f1
LinuxLinux5.16, 0, 5.10.265
linuxlinux_kernel5.10.84, 5.15.7, 5.16
LinuxLinux209d35ee34e25f9668c404350a1c86d914c54ffa, 8ef8a76a340ebdb2c2eea3f6fb0ebbed09a16383, cdef485217d30382f3bf6448c54b4401648fe3f1

Timeline

  • Aug 21, 2026 CVE Published
  • Aug 22, 2026 Coalition ESS Score
  • Aug 24, 2026 EPSS Score
  • Aug 25, 2026 EPSS Score
  • Aug 25, 2026 CVE Updated
  • Aug 26, 2026 Distribution Patch
  • Aug 26, 2026 Security Advisory
  • Aug 27, 2026 EPSS Score
  • Aug 29, 2026 Distribution Patch
  • Aug 29, 2026 Security Advisory
  • Aug 30, 2026 Distribution Patch
  • Aug 30, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›