{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74630","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.921Z","datePublished":"2026-08-22T15:32:11.596Z","dateUpdated":"2026-08-25T05:40:54.475Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-25T05:40:54.475Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent in6_dev_get() from resurrecting inet6_dev\n\nin6_dev_get() reads dev->ip6_ptr under RCU and then unconditionally\nincrements its refcount. Device teardown can clear the pointer and drop\nthe last reference between these operations. The increment then\nresurrects an object whose RCU free has already been queued, so callers\ncan use it after it is freed.\n\nUse refcount_inc_not_zero() and return NULL when the object has already\nreached zero. RCU keeps the memory accessible through the attempted\nreference acquisition, and a successful increment pins the object for\nthe caller.\n\nAn independent run on the exact unpatched 6f5156d7a31a (v7.2-rc3)\nkernel reproduced the invalid reference acquisition as UID 1000:\n\n  refcount_t: addition on 0; use-after-free.\n  ip6_mc_source+0xef4/0x17e0\n\nIt was followed by the corresponding reference underflow in\nip6_mc_source(). The supplied trace from the same unpatched revision\nadditionally shows the access after the RCU read-side section ends:\n\n  BUG: KASAN: slab-use-after-free in mutex_lock+0x76/0xe0\n  Write of size 8 at addr ffff888015b50240 by task poc/1219\n\nBug found and triaged by OpenAI Security Research and\nvalidated by Trail of Bits."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The reliable path is local setsockopt(2) on IPv6 MCAST source-filter options (ipv6_setsockopt → do_ipv6_mcast_group_source → ip6_mc_source → in6_dev_get), reproduced as UID 1000; concurrent netdev unregister is also a local rtnetlink syscall, not remote packet delivery.\nAC:L - An attacker in their own user+network namespace controls both sides of the race—hammering MCAST_JOIN/BLOCK/UNBLOCK_SOURCE setsockopt while deleting the bound veth via RTM_DELLINK—so the ip6_ptr clear and final in6_dev_put window is attacker-driven and retryable.\nPR:L - Multicast setsockopt needs no capability, but hitting the unregister teardown that drops the last inet6_dev reference requires CAP_NET_ADMIN for RTM_DELLINK; that is ns_capable() in the netns user_ns and is obtainable by an unprivileged user via unshare -Urn, not init-namespace root.\nUI:N - Exploitation uses only the attacker's own IPv6 sockets, setsockopt calls, and netdev create/delete in their namespace; no victim mount, click, or other cooperation is required.\nS:U - The resurrected inet6_dev UAF corrupts kernel heap state within the host kernel authority (mutex_lock on freed mc_lock); it is standard local kernel memory corruption, not a VM escape, IOMMU bypass, or other cross-boundary impact.\nC:H - Resurrecting a zero-refcount inet6_dev whose RCU free is already queued is a slab use-after-free; KASAN reported UAF on freed inet6_dev memory, and such heap UAFs enable disclosure via controlled reuse of the freed object.\nI:H - After resurrection the caller locks idev->mc_lock and mutates multicast state on freed memory (KASAN write in mutex_lock), giving attacker-influenced heap corruption that can be turned into arbitrary write or control-flow hijack.\nA:H - The PoC triggers refcount_t addition-on-0 warnings, refcount underflow, and KASAN slab-use-after-free in mutex_lock, demonstrating immediate kernel memory corruption that can oops/panic and be repeated by re-running the race."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/addrconf.h"],"versions":[{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"785d908f8d21c8bc78b6fb2c2932ab662bf6918a","status":"affected","versionType":"git"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"aedcfefdb5b7ed7f8a6196a3e68a25bdbe51d2f8","status":"affected","versionType":"git"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"145812b678de9f3b59780173be3c0d22ed60dd93","status":"affected","versionType":"git"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"cc5bd568f9b7683e60841b6fd02c10d64535bd6e","status":"affected","versionType":"git"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"1c206d461c680c3151daa3c89fc26eaf5bf98a7f","status":"affected","versionType":"git"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"680fbd7942185448eadb990a3d10a53eb946b702","status":"affected","versionType":"git"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"14e812ab41df0cac033479da835ec9a5de633404","status":"affected","versionType":"git"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"0e243671bc7b8eaf00f83dd2f4367436dc0cff98","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/addrconf.h"],"versions":[{"version":"2.6.19","status":"affected"},{"version":"0","lessThan":"2.6.19","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.6.152"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.12.104"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.18.45"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"7.1.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/785d908f8d21c8bc78b6fb2c2932ab662bf6918a"},{"url":"https://git.kernel.org/stable/c/aedcfefdb5b7ed7f8a6196a3e68a25bdbe51d2f8"},{"url":"https://git.kernel.org/stable/c/145812b678de9f3b59780173be3c0d22ed60dd93"},{"url":"https://git.kernel.org/stable/c/cc5bd568f9b7683e60841b6fd02c10d64535bd6e"},{"url":"https://git.kernel.org/stable/c/1c206d461c680c3151daa3c89fc26eaf5bf98a7f"},{"url":"https://git.kernel.org/stable/c/680fbd7942185448eadb990a3d10a53eb946b702"},{"url":"https://git.kernel.org/stable/c/14e812ab41df0cac033479da835ec9a5de633404"},{"url":"https://git.kernel.org/stable/c/0e243671bc7b8eaf00f83dd2f4367436dc0cff98"}],"title":"ipv6: prevent in6_dev_get() from resurrecting inet6_dev","x_generator":{"engine":"bippy-1.2.0"}}}}