{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74492","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.906Z","datePublished":"2026-08-15T12:27:21.365Z","dateUpdated":"2026-08-19T16:37:48.078Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:37:48.078Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: do not update comments from kernel-side hash adds\n\nmtype_resize() copies comment pointers with memcpy(), not the comment\nobjects themselves. During the window after an entry has been copied but\nbefore the table swap and backlog replay, the old table is still\npublished for packet-side updates while the replacement-table entry\nalready holds the same ip_set_comment_rcu pointer.\n\nIf xt_SET --add-set ... --exist hits that old entry in this window,\nmtype_add() calls ip_set_init_comment() even though packet-side adds\ncarry no comment payload. That call frees the shared comment through the\nold entry, so the replacement-table entry now holds a stale pointer.\nWhen the queued add is replayed on the new table, mtype_add() calls\nip_set_init_comment() again and strlen() dereferences the stale pointer.\n\nFix this in mtype_add() by skipping ip_set_init_comment() when\next->target marks a packet-side add. Userspace adds still update\ncomments, while packet-side adds can no longer free comment storage\nshared with a resize copy."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached via the netfilter xt_SET packet path (set_target_* -> ip_set_add -> kadt -> mtype_add) during skb processing in iptables hooks; kernel CNA guidance treats netfilter/ipset as Local even when triggering packets arrive from the network.\nAC:L - An attacker can drive both sides of the resize race by filling a comment-enabled hash set and concurrently sending packets that hit SET --add-set --exist while mtype_resize() copies entries, making the shared-comment UAF window repeatable rather than dependent on uncontrollable timing.\nPR:N - Exploitation requires only sending traffic that matches an already-installed SET --exist rule on a comment-enabled ipset during resize; no local account or CAP_NET_ADMIN is needed, though unprivileged user namespaces can also obtain CAP_NET_ADMIN to configure the full attack chain.\nUI:N - Triggering is fully automatic through netfilter packet handling once the vulnerable ipset/iptables configuration exists; the attacker does not need the victim to click, mount, or perform any deliberate action beyond ordinary packet delivery.\nS:U - The flaw corrupts kernel heap memory and can yield host privilege escalation, but it does not cross a distinct security authority such as a VM/host, container/host, or IOMMU boundary; impact remains within the same kernel security domain.\nC:H - Packet-side mtype_add() frees a shared ip_set_comment_rcu during resize, leaving duplicate entries with dangling pointers; backlog replay calls ip_set_init_comment() and strlen() on freed kmalloc memory, a classic UAF that can disclose arbitrary kernel data with heap grooming.\nI:H - The UAF over RCU-freed comment objects lets an attacker reclaim and control freed slab memory, providing a standard path to arbitrary kernel writes, metadata corruption, and control-flow hijack rather than a bounded or crash-only integrity effect.\nA:H - Stale comment pointer dereference during resize backlog replay can immediately kernel-oops/panic the host, and the underlying UAF heap corruption can crash or hang the system even when full exploitation is not attempted."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/ipset/ip_set_hash_gen.h"],"versions":[{"version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","lessThan":"6f13f4d52d06986c18f12e8bffaab944dd27ceab","status":"affected","versionType":"git"},{"version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","lessThan":"f9d6cabff1fca010562dcdb0d22b296bdca3ba5a","status":"affected","versionType":"git"},{"version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","lessThan":"16bfa7be2d76ca1e0aacfa363482e1bf8ab5042a","status":"affected","versionType":"git"},{"version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","lessThan":"661ff9c0cfbe07f8eed920dde9f7781491738207","status":"affected","versionType":"git"},{"version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","lessThan":"c710e9bf38e4e71a8db85d26a0f70c0674664207","status":"affected","versionType":"git"},{"version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","lessThan":"4ae701848e4ba9e9713375fb7d82218cbd309da2","status":"affected","versionType":"git"},{"version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","lessThan":"77dbb248a5cc7a5270cd37bbb0b635bf059a872a","status":"affected","versionType":"git"},{"version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","lessThan":"f30415929be8aeb002d557c8d3f7ab2d2188003a","status":"affected","versionType":"git"},{"version":"5dd9488ae41070b69d2f4acb580f77db5705f9ca","status":"affected","versionType":"git"},{"version":"a469bab3386aebff33c59506f3a95e35b91118fd","status":"affected","versionType":"git"},{"version":"5.4.24","lessThan":"5.5","status":"affected","versionType":"semver"},{"version":"5.5.8","lessThan":"5.6","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/ipset/ip_set_hash_gen.h"],"versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.6.151"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.12.103"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.18.44"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.1.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.24"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6f13f4d52d06986c18f12e8bffaab944dd27ceab"},{"url":"https://git.kernel.org/stable/c/f9d6cabff1fca010562dcdb0d22b296bdca3ba5a"},{"url":"https://git.kernel.org/stable/c/16bfa7be2d76ca1e0aacfa363482e1bf8ab5042a"},{"url":"https://git.kernel.org/stable/c/661ff9c0cfbe07f8eed920dde9f7781491738207"},{"url":"https://git.kernel.org/stable/c/c710e9bf38e4e71a8db85d26a0f70c0674664207"},{"url":"https://git.kernel.org/stable/c/4ae701848e4ba9e9713375fb7d82218cbd309da2"},{"url":"https://git.kernel.org/stable/c/77dbb248a5cc7a5270cd37bbb0b635bf059a872a"},{"url":"https://git.kernel.org/stable/c/f30415929be8aeb002d557c8d3f7ab2d2188003a"}],"title":"netfilter: ipset: do not update comments from kernel-side hash adds","x_generator":{"engine":"bippy-1.2.0"}}}}