๐Ÿ” CVE Alert

CVE-2026-74478

UNKNOWN 0.0

um: vector: fix use-after-free in vector_mmsg_rx()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: um: vector: fix use-after-free in vector_mmsg_rx() When vector_mmsg_rx() discards a packet whose overlay header fails verify_header(), it frees the skb and continues the loop: if (header_check < 0) { dev_kfree_skb_irq(skb); vp->estats.rx_encaps_errors++; continue; } The normal and short-packet paths fall through to the bottom of the loop body, which clears the consumed slot and advances the cursors: (*skbuff_vector) = NULL; mmsg_vector++; skbuff_vector++; The verify_header() < 0 path skips that via continue, so the freed skb is left in skbuff_vector[] and the cursors do not advance. The next iteration reads the same slot, gets the freed skb, and frees it again, producing a refcount underflow / use-after-free in the RX path. Discard the slot the same way the other paths do before continuing. Only transports whose verify_header() can return negative are affected: GRE and L2TPv3 do so on a cookie/session-id mismatch (raw/tap do not), so any peer on such a transport can trigger it without authentication.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < 4b9601595e8b6b5d18878cac0aeabc687d241111 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < 67d58ab4f2ccf7145f3da07e025735a09c79de1b 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < 180ff4c81faf01ec4e06082c9daa7c40518ead89 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < 804b681002ead233abf49a3efd681f5468a835f9 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < af421e9aed3920c7ac88c24daa48606c7112feca
Linux / Linux
4.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/4b9601595e8b6b5d18878cac0aeabc687d241111 git.kernel.org: https://git.kernel.org/stable/c/67d58ab4f2ccf7145f3da07e025735a09c79de1b git.kernel.org: https://git.kernel.org/stable/c/180ff4c81faf01ec4e06082c9daa7c40518ead89 git.kernel.org: https://git.kernel.org/stable/c/804b681002ead233abf49a3efd681f5468a835f9 git.kernel.org: https://git.kernel.org/stable/c/af421e9aed3920c7ac88c24daa48606c7112feca