← All Advisories

CVE-2026-74743

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-74743

Key Details

CVECVE-2026-74743
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

macvlan: inherit needed_headroom and needed_tailroom from lowerdev

macvlan devices inherit hard_header_len from lowerdev during macvlan_init(),

but leave needed_headroom and needed_tailroom set to 0.

When the underlying lowerdev requires extra headroom or tailroom for

headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx

headroom), upper layers calculating packet headroom and tailroom fail to

reserve sufficient space.

This can result in reallocation overhead, skb headroom underflows, or KASAN

slab-use-after-free crashes when dev_hard_header() / macvlan_hard_header()

prepends header data or when lower devices append tailroom.

Fix this by:

1. Inheriting needed_headroom and needed_tailroom from lowerdev in macvlan_init().

2. Propagating needed_headroom and needed_tailroom updates to attached macvlans

in macvlan_device_event() when receiving NETDEV_FEAT_CHANGE events. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-74743
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-74743