9.8

CVE-2026-74478

um: vector: fix use-after-free in vector_mmsg_rx()

In the Linux kernel, the following vulnerability has been resolved:

um: vector: fix use-after-free in vector_mmsg_rx()

When vector_mmsg_rx() discards a packet whose overlay header fails
verify_header(), it frees the skb and continues the loop:

	if (header_check < 0) {
		dev_kfree_skb_irq(skb);
		vp->estats.rx_encaps_errors++;
		continue;
	}

The normal and short-packet paths fall through to the bottom of the
loop body, which clears the consumed slot and advances the cursors:

	(*skbuff_vector) = NULL;
	mmsg_vector++;
	skbuff_vector++;

The verify_header() < 0 path skips that via continue, so the freed skb
is left in skbuff_vector[] and the cursors do not advance. The next
iteration reads the same slot, gets the freed skb, and frees it again,
producing a refcount underflow / use-after-free in the RX path.

Discard the slot the same way the other paths do before continuing.

Only transports whose verify_header() can return negative are affected:
GRE and L2TPv3 do so on a cookie/session-id mismatch (raw/tap do not),
so any peer on such a transport can trigger it without authentication.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb
Version < 967c779c9853d2a1cc9cd8e61d300250c348f3d9
Status affected
Version 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb
Version < a7bc015bb798c525e7a82dd14225c6aeb994274b
Status affected
Version 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb
Version < 7dc9781e320d664c9bdd50003c9acfddf363d1e1
Status affected
Version 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb
Version < 4b9601595e8b6b5d18878cac0aeabc687d241111
Status affected
Version 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb
Version < 67d58ab4f2ccf7145f3da07e025735a09c79de1b
Status affected
Version 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb
Version < 180ff4c81faf01ec4e06082c9daa7c40518ead89
Status affected
Version 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb
Version < 804b681002ead233abf49a3efd681f5468a835f9
Status affected
Version 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb
Version < af421e9aed3920c7ac88c24daa48606c7112feca
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.17
Status affected
Version 0
Version < 4.17
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.449
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4b9601595e8b6b5d18878cac0aeabc687d241111
https://git.kernel.org/stable/c/67d58ab4f2ccf7145f3da07e025735a09c79de1b
https://git.kernel.org/stable/c/180ff4c81faf01ec4e06082c9daa7c40518ead89
https://git.kernel.org/stable/c/804b681002ead233abf49a3efd681f5468a835f9
https://git.kernel.org/stable/c/af421e9aed3920c7ac88c24daa48606c7112feca
https://git.kernel.org/stable/c/7dc9781e320d664c9bdd50003c9acfddf363d1e1
https://git.kernel.org/stable/c/967c779c9853d2a1cc9cd8e61d300250c348f3d9
https://git.kernel.org/stable/c/a7bc015bb798c525e7a82dd14225c6aeb994274b