Answer in brief
CVE-2026-74746 records a Unknown severity vulnerability in netfilter: flowtable: publish GC-visible tuple last. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ac2a66665e231847cab11b8c8e844ce43207dd2e <0a00254585827f1695aa2700114af622ea754cfa || >=ac2a66665e231847cab11b8c8e844ce43207dd2e <be345dcbddb4643a54252b954af974b16eda8f91 || >=ac2a66665e231847cab11b8c8e844ce43207dd2e <211ee5d998d92a7d548811939c65942d06c146e4 || >=ac2a66665e231847cab11b8c8e844ce43207dd2e <d37917e7bebe078f3c17e47fd6fc1c9f6e8497b2 || >=ac2a66665e231847cab11b8c8e844ce43207dd2e <972fdf7c4f5c282a239c88fea614b056c33dc025 || >=ac2a66665e231847cab11b8c8e844ce43207dd2e <d9d3050a70efe217e73a0751e55fdae6a7092620 || >=ac2a66665e231847cab11b8c8e844ce43207dd2e <d16b71231e65cb05daea2b45701fcf09cef041e7 || >=ac2a66665e231847cab11b8c8e844ce43207dd2e <2014ac62df9d45bb9a004a043e85df7be09ed780 | 0a00254585827f1695aa2700114af622ea754cfa, be345dcbddb4643a54252b954af974b16eda8f91, 211ee5d998d92a7d548811939c65942d06c146e4, d37917e7bebe078f3c17e47fd6fc1c9f6e8497b2, 972fdf7c4f5c282a239c88fea614b056c33dc025, d9d3050a70efe217e73a0751e55fdae6a7092620, d16b71231e65cb05daea2b45701fcf09cef041e7, 2014ac62df9d45bb9a004a043e85df7be09ed780 |
| Linux/Linuxgeneric | 4.16 | Not reported |
Published upstream
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 26, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() only treats original-direction tuple nodes as owning entries. Publishing the original node first lets GC observe and free a flow while flow_offload_add() is still inserting the reply node. Publish the reply node first and the original node last so GC never sees a partially installed flow. KASAN can trigger slab-use-after-free read and write reports in the flowtable/rhashtable path (rht_deferred_worker, jhash, flow_offload_del, flow_offload_lookup, etc.).
Quoted source text, attributed separately from HOL analysis.