← All Advisories

CVE-2026-74289

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-74289

Key Details

CVECVE-2026-74289
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ipv4: fib: Don't dump dying fib_info in fib_leaf_notify().

syzbot reported use-after-free in nsim_fib4_prepare_event(). [0]

The problem is that the following functions call fib_info_hold() /

refcount_inc() while dumping fib_info under RCU, which is unsafe.

* mlxsw_sp_router_fib4_event()

* rocker_router_fib_event()

* nsim_fib4_prepare_event()

refcount_inc_not_zero() must be used, but it would be too late

there.

Let's guarantee the lifetime of fib_info in fib_leaf_notify().

Note that IPv6 does not need the corresponding change since

fib6_table_dump() holds fib6_table.tb6_lock.

[0]:

refcount_t: addition on 0; use-after-free.

WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25, CPU#0: kworker/u8:15/3420

Modules linked in:

CPU: 0 UID: 0 PID: 3420 Comm: kworker/u8:15 Not tainted syzkaller #0 PREEMPT_{RT,(full)}

Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026

Workqueue: netns cleanup_net

RIP: 0010:refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25

Code: eb 66 85 db 74 3e 83 fb 01 75 4c e8 1b f1 22 fd 48 8d 3d 84 cb f1 0a 67 48 0f b9 3a eb 4a e8 08 f1 22 fd 48 8d 3d 81 cb f1 0a <67> 48 0f b9 3a eb 37 e8 f5 f0 22 fd 48 8d 3d 7e cb f1 0a 67 48 0f

RSP: 0018:ffffc9000f2c7270 EFLAGS: 00010293

RAX: ffffffff84a18858 RBX: 0000000000000002 RCX: ffff888032ff9ec0

RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff8f9353e0

RBP: 0000000000000000 R08: ffff888032ff9ec0 R09: 0000000000000005

R10: 0000000000000100 R11: 0000000000000004 R12: ffff8880570cc000

R13: dffffc0000000000 R14: ffff88802b40563c R15: ffff8880570cc000

FS: 0000000000000000(0000) GS:ffff888126173000(0000) knlGS:0000000000000000

CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033

CR2: 00007fb1f4d5d000 CR3: 000000006072a000 CR4: 00000000003526f0

Call Trace:

<TASK>

__refcount_add include/linux/refcount.h:-1 [inline]

__refcount_inc include/linux/refcount.h:366 [inline]

refcount_inc include/linux/refcount.h:383 [inline]

fib_info_hold include/net/ip_fib.h:629 [inline]

nsim_fib4_prepare_event drivers/net/netdevsim/fib.c:930 [inline]

nsim_fib_event_schedule_work drivers/net/netdevsim/fib.c:1000 [inline]

nsim_fib_event_nb+0x1055/0x1240 drivers/net/netdevsim/fib.c:1043

call_fib_notifier+0x45/0x80 net/core/fib_notifier.c:25

call_fib_entry_notifier net/ipv4/fib_trie.c:90 [inline]

fib_leaf_notify net/ipv4/fib_trie.c:2176 [inline]

fib_table_notify net/ipv4/fib_trie.c:2194 [inline]

fib_notify+0x36b/0x5e0 net/ipv4/fib_trie.c:2217

fib_net_dump net/core/fib_notifier.c:70 [inline]

register_fib_notifier+0x184/0x360 net/core/fib_notifier.c:108

nsim_fib_create+0x85d/0x9f0 drivers/net/netdevsim/fib.c:1596

nsim_dev_reload_create drivers/net/netdevsim/dev.c:1604 [inline]

nsim_dev_reload_up+0x374/0x7c0 drivers/net/netdevsim/dev.c:1058

devlink_reload+0x501/0x8d0 net/devlink/dev.c:475

devlink_pernet_pre_exit+0x1ff/0x420 net/devlink/core.c:558

ops_pre_exit_list net/core/net_namespace.c:161 [inline]

ops_undo_list+0x187/0x940 net/core/net_namespace.c:234

cleanup_net+0x56e/0x800 net/core/net_namespace.c:702

process_one_work kernel/workqueue.c:3314 [inline]

process_scheduled_works+0xb5d/0x1860 kernel/workqueue.c:3397

worker_thread+0xa53/0xfc0 kernel/workqueue.c:3478

kthread+0x388/0x470 kernel/kthread.c:436

ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158

ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245

</TASK> (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-74289
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-74289