CVE-2026-74283
CVE CVE-2026-74283EUVD EUVD-2026-59430Published 2026-08-15T05:57:52.000ZLast changed 2026-08-17T05:45:24.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: tipc: require net admin for TIPCv2 netlink mutators TIPCv2 registers mutating generic-netlink operations without admin permission flags. Generic netlink only checks CAP_NET_ADMIN when an operation sets GENL_ADMIN_PERM or GENL_UNS_ADMIN_PERM, so a local unprivileged process can currently change TIPC state through commands such as TIPC_NL_NET_SET, TIPC_NL_KEY_SET, TIPC_NL_KEY_FLUSH, and bearer enable/disable. The legacy TIPC netlink API already checks netlink_net_capable(..., CAP_NET_ADMIN) for administrative commands. Give the TIPCv2 mutators the equivalent generic-netlink gate. Use GENL_UNS_ADMIN_PERM, which maps to the same namespace-aware CAP_NET_ADMIN check that netlink_net_capable() performs, so the behaviour matches the legacy path and keeps working for CAP_NET_ADMIN holders in a non-initial user namespace (containers). A QEMU/KASAN repro run as uid/gid 65534 with zero effective capabilities previously succeeded in changing the network id and node identity, setting and flushing key material, and enabling/disabling a UDP bearer. With this patch applied the same operations fail with -EPERM.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 0655f6a8635b1b66f2434d5556b1044c14b1ccaf <e87dcc1a644d087de0bb6c94c6dd28c29b89597f; 0655f6a8635b1b66f2434d5556b1044c14b1ccaf <9b937de4b3ded62a24da6e8d9d623cdb2748fa74; patch: 6.18.40; patch: 6.6.145; 0655f6a8635b1b66f2434d5556b1044c14b1ccaf <cebaefe1aceb650d5c99a4c0e1a4dde09e211818; patch: 6.12.97; patch: 6.1.178; patch: 5.15.212; patch: 5.10.261; 3.19; 0655f6a8635b1b66f2434d5556b1044c14b1ccaf <86b0c540e2ea397cde021eecd24145f7c16a3d4e; 0655f6a8635b1b66f2434d5556b1044c14b1ccaf <b06fb5f78a9af0929aaa47c92d0b7bca0617fb25; patch: 0; 0655f6a8635b1b66f2434d5556b1044c14b1ccaf <56f0a2e0a1d004e025cd031c3a801ab73959269f; patch: 7.1.5; 0655f6a8635b1b66f2434d5556b1044c14b1ccaf <52864c6c13dcc292481eabfeb3c31a86c3ec06f2; patch: 7.2; 0655f6a8635b1b66f2434d5556b1044c14b1ccaf <c9668a4adb2264625daeeabc7466b783badd4614
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.