Answer in brief
CVE-2026-74609 records a High severity (CVSS 7.8) vulnerability in tipc: read le->link under the node lock in tipc_node_link_down(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=73f646cec35477b5099d7e952297cb9e1855be45 <2be741ad565c610871a6a95062c12c39da7168fd || >=73f646cec35477b5099d7e952297cb9e1855be45 <69d209461c110388710e483a130caf051e4fd09a || >=73f646cec35477b5099d7e952297cb9e1855be45 <de017c22135f545ca4e65d1eada22887b64958eb || >=73f646cec35477b5099d7e952297cb9e1855be45 <47ba70891b10b2feb52462086b7fcd2ad75d3ce3 || >=73f646cec35477b5099d7e952297cb9e1855be45 <a714d62513befef37f71f4ae89bb1fe173b65f2e || >=73f646cec35477b5099d7e952297cb9e1855be45 <c3f2347a47754eac690967cfd82cb6d559817b07 || >=73f646cec35477b5099d7e952297cb9e1855be45 <5558a8312452ddb21eff22b1cbd84302ad951944 || >=73f646cec35477b5099d7e952297cb9e1855be45 <cba9ccb47e9fa4cc77692fb896cc5ab57a667882 | 2be741ad565c610871a6a95062c12c39da7168fd, 69d209461c110388710e483a130caf051e4fd09a, de017c22135f545ca4e65d1eada22887b64958eb, 47ba70891b10b2feb52462086b7fcd2ad75d3ce3, a714d62513befef37f71f4ae89bb1fe173b65f2e, c3f2347a47754eac690967cfd82cb6d559817b07, 5558a8312452ddb21eff22b1cbd84302ad951944, cba9ccb47e9fa4cc77692fb896cc5ab57a667882 |
| Linux/Linuxgeneric | 4.4 | Not reported |
Published upstream
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 22, 2026
In the Linux kernel, the following vulnerability has been resolved: tipc: read le->link under the node lock in tipc_node_link_down() tipc_node_link_down() caches the link pointer before taking n->lock: struct tipc_link *l = le->link; /* unlocked */ if (!l) return; tipc_node_write_lock(n); if (!tipc_link_is_establishing(l)) { /* deref l */ ... tipc_link_reset(l); /* write into l */ if (delete) { kfree(l); le->link = NULL; The delete=true caller frees that very object under n->lock, so the lock does not protect the cached pointer against it: - CPU A, delete=false: tipc_rcv() on TIPC_LINK_DOWN_EVT, or the link supervision timer via tipc_node_timeout(), reads l unlocked and then dereferences it under n->lock; - CPU B, delete=true: netlink TIPC_NL_BEARER_DISABLE -> bearer_disable() -> tipc_node_delete_links() -> tipc_node_link_down(n, bearer_id, true) -> kfree(l). The link is freed with plain kfree(), not kfree_rcu(), and for UDP bearers disable_media() only schedules the asynchronous cleanup_bearer() work, so its synchronize_net() runs after the links are already gone. An in-flight CPU A that has read l therefore dereferences freed memory once B frees it: a use-after-free read in tipc_link_is_establishing(), and a use-after-free write via tipc_link_reset() on the establishing branch. The following trace was captured on 7.2.0-rc5-00284-gaf39eb111ce6: BUG: KASAN: slab-use-after-free in tipc_link_is_establishing (net/tipc/link.c:285) Read of size 4 at addr ffff88802e2aa068 by task swapper/2/0 tipc_link_is_establishing (net/tipc/link.c:285) tipc_node_link_down (net/tipc/node.c:1076) tipc_node_timeout (net/tipc/node.c:843) Allocated by task 9549: tipc_link_create (net/tipc/link.c:490) tipc_node_check_dest (net/tipc/node.c:1279) tipc_disc_rcv (net/tipc/discover.c:252) tipc_udp_recv (net/tipc/udp_media.c:389) Freed by task 9549: tipc_node_link_down (net/tipc/node.c:1084) tipc_node_delete_links (net/tipc/node.c:1320) bearer_disable (net/tipc/bearer.c:414) __tipc_nl_bearer_disable (net/tipc/bearer.c:992) Move the le->link read inside tipc_node_write_lock(), so it is serialised against the kfree() in the delete path. A racing teardown now either has not run yet, and we see a valid link, or has already run, and we see NULL.
Quoted source text, attributed separately from HOL analysis.