← All Advisories

CVE-2026-74496

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-74496

Key Details

CVECVE-2026-74496
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

fou: Fix use-after-free in fou_create()

fou_create() publishes struct fou through sk_user_data before adding the

new FOU port to the per-netns list. If fou_add_to_port_list() fails,

the error path frees fou while it is still reachable through

sk_user_data. A concurrent receive can then dereference the freed

object in fou_from_sock().

This ordering issue was previously noted in the linked discussion.

The failure is reachable when local port 0 is requested. Each socket

binds to a different ephemeral port, but fou_cfg_cmp() compares the

requested port 0 and reports -EALREADY once an entry already exists.

Release the tunnel socket before freeing fou so sk_user_data is cleared

first, and defer reclamation with kfree_rcu() to protect concurrent RCU

readers. This matches the lifetime handling in fou_release(). (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-74496
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-74496