Answer in brief
CVE-2026-74255 records a Unknown severity vulnerability in tipc: fix UAF in tipc_l2_send_msg(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-74255 records a Unknown severity vulnerability in tipc: fix UAF in tipc_l2_send_msg(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=282b3a056225b35024246f63feb91d769d714dad <609ced2301be1df7e7ed2ef47d1d916674e6ba3b || >=282b3a056225b35024246f63feb91d769d714dad <71aafa16d79b107b33837f60b6cbc7d0cb8c5708 || >=282b3a056225b35024246f63feb91d769d714dad <f4002f1c669cc02e3763f479fc25ff1dfa9e2420 || >=282b3a056225b35024246f63feb91d769d714dad <50ff092633b06382e5091dd5b093ce943d4ac2f9 || >=282b3a056225b35024246f63feb91d769d714dad <aef12b5ce793dea6b3a97a58fd0f946000ae8945 || >=282b3a056225b35024246f63feb91d769d714dad <0d8a12d7143126afdf9fbe2e3d438650dd6603ed || >=282b3a056225b35024246f63feb91d769d714dad <35e0297a93c3c34a3924eeef816c03504e3ab5c5 || >=282b3a056225b35024246f63feb91d769d714dad <f4c3d89fc986b0da196ddfc6cfe0ea5d5d08bec6 | 609ced2301be1df7e7ed2ef47d1d916674e6ba3b, 71aafa16d79b107b33837f60b6cbc7d0cb8c5708, f4002f1c669cc02e3763f479fc25ff1dfa9e2420, 50ff092633b06382e5091dd5b093ce943d4ac2f9, aef12b5ce793dea6b3a97a58fd0f946000ae8945, 0d8a12d7143126afdf9fbe2e3d438650dd6603ed, 35e0297a93c3c34a3924eeef816c03504e3ab5c5, f4c3d89fc986b0da196ddfc6cfe0ea5d5d08bec6 |
| Linux/Linuxgeneric | 4.4 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in tipc_l2_send_msg() Syzbot reported a slab-use-after-free in ipvlan_hard_header() when called from tipc_l2_send_msg(). The root cause is that tipc_disable_l2_media() calls synchronize_net() while b->media_ptr is still valid. This allows concurrent RCU readers to obtain the device pointer after synchronize_net() has finished. The pointer is cleared later in bearer_disable(), but without any subsequent synchronization, allowing the device to be freed while still in use by readers. Fix this by clearing b->media_ptr in tipc_disable_l2_media() before calling synchronize_net(). This is safe to do now because the call order in bearer_disable() was reversed in 0d051bf93c06 ("tipc: make bearer packet filtering generic") to call tipc_node_delete_links() (which needs the pointer) before disable_media(). https: //lore.kernel.org/netdev/[email protected]/T/#u
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=282b3a056225b35024246f63feb91d769d714dad <609ced2301be1df7e7ed2ef47d1d916674e6ba3b || >=282b3a056225b35024246f63feb91d769d714dad <71aafa16d79b107b33837f60b6cbc7d0cb8c5708 || >=282b3a056225b35024246f63feb91d769d714dad <f4002f1c669cc02e3763f479fc25ff1dfa9e2420 || >=282b3a056225b35024246f63feb91d769d714dad <50ff092633b06382e5091dd5b093ce943d4ac2f9 || >=282b3a056225b35024246f63feb91d769d714dad <aef12b5ce793dea6b3a97a58fd0f946000ae8945 || >=282b3a056225b35024246f63feb91d769d714dad <0d8a12d7143126afdf9fbe2e3d438650dd6603ed || >=282b3a056225b35024246f63feb91d769d714dad <35e0297a93c3c34a3924eeef816c03504e3ab5c5 || >=282b3a056225b35024246f63feb91d769d714dad <f4c3d89fc986b0da196ddfc6cfe0ea5d5d08bec6 | 609ced2301be1df7e7ed2ef47d1d916674e6ba3b, 71aafa16d79b107b33837f60b6cbc7d0cb8c5708, f4002f1c669cc02e3763f479fc25ff1dfa9e2420, 50ff092633b06382e5091dd5b093ce943d4ac2f9, aef12b5ce793dea6b3a97a58fd0f946000ae8945, 0d8a12d7143126afdf9fbe2e3d438650dd6603ed, 35e0297a93c3c34a3924eeef816c03504e3ab5c5, f4c3d89fc986b0da196ddfc6cfe0ea5d5d08bec6 |
| Linux/Linuxgeneric | 4.4 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in tipc_l2_send_msg() Syzbot reported a slab-use-after-free in ipvlan_hard_header() when called from tipc_l2_send_msg(). The root cause is that tipc_disable_l2_media() calls synchronize_net() while b->media_ptr is still valid. This allows concurrent RCU readers to obtain the device pointer after synchronize_net() has finished. The pointer is cleared later in bearer_disable(), but without any subsequent synchronization, allowing the device to be freed while still in use by readers. Fix this by clearing b->media_ptr in tipc_disable_l2_media() before calling synchronize_net(). This is safe to do now because the call order in bearer_disable() was reversed in 0d051bf93c06 ("tipc: make bearer packet filtering generic") to call tipc_node_delete_links() (which needs the pointer) before disable_media(). https: //lore.kernel.org/netdev/[email protected]/T/#u
Quoted source text, attributed separately from HOL analysis.