CVE-2026-74660
CVE CVE-2026-74660EUVD EUVD-2026-64347Published 2026-08-22T15:32:33.000ZLast changed 2026-08-25T05:41:14.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebt_nflog: pin the NFLOG backend nf_log_unregister() runs after the per-net teardown so its final RCU grace period also drains readers that obtained the logger from a per-net binding. However, ebt_nflog passes an explicit ULOG log type to nf_log_packet() without holding a reference on the selected logger module, unlike the xt_NFLOG and nft_log frontends. An ebtables nflog rule can therefore remain callable while nfnetlink_log is unloaded. The resulting interleaving is: CPU 0 CPU 1 nfnetlink_log_fini() unregister_pernet_subsys() kfree(nfnl_log_pernet(net)) ebt_nflog_tg() nf_log_packet() nfulnl_log_packet() instance_lookup_get_rcu() The global ULOG logger is still registered at this point, so CPU 1 dereferences the per-net state after CPU 0 has freed it. KASAN reported: BUG: KASAN: slab-use-after-free in instance_lookup_get_rcu Read of size 8 at addr ff110001052e6210 by task poc/92 Call Trace: instance_lookup_get_rcu+0x1ce/0x1f0 [nfnetlink_log] nfulnl_log_packet+0x248/0x2fb0 [nfnetlink_log] nf_log_packet+0x204/0x300 ebt_nflog_tg+0x351/0x550 ebt_do_table+0xedf/0x22b0 Allocated by task 90: __kmalloc_noprof+0x186/0x470 ops_init+0x6d/0x420 register_pernet_operations+0x2f6/0x670 register_pernet_subsys+0x23/0x40 Freed by task 93: kfree+0x131/0x3c0 ops_undo_list+0x3e3/0x700 unregister_pernet_operations+0x232/0x490 unregister_pernet_subsys+0x1c/0x30 nfnetlink_log_fini+0x34/0x450 [nfnetlink_log] Acquire the ULOG logger module reference when an ebt_nflog rule is validated and release it when the rule is destroyed. Request the NFLOG backend for legacy callers when needed, matching xt_NFLOG. This prevents module teardown until all ebt_nflog rules have stopped using the logger.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux c83fa19603bdaeef17b815713dbbe3230c8a34ee <2cac4294f184c9bc19ff82552c62b80498694c39; c83fa19603bdaeef17b815713dbbe3230c8a34ee <394d7939c6b2b9e6bea0844c89efb5913168d898; c83fa19603bdaeef17b815713dbbe3230c8a34ee <3bcce49d617c593c7606083bfdb464a1761fa68d; c83fa19603bdaeef17b815713dbbe3230c8a34ee <30825970339c107bacaf7f61af90fcdb1f597ca1; patch: 6.18.45; patch: 6.12.104; patch: 5.15.216; patch: 5.10.265; patch: 0; patch: 7.1.9; c83fa19603bdaeef17b815713dbbe3230c8a34ee <47a119ec8a7e2d5c8c4e86fb1a56c4e696e500fb; patch: 6.6.152; patch: 7.2; c83fa19603bdaeef17b815713dbbe3230c8a34ee <9d8a94b48b393885e7f876c8ef68ed4da5012078; 4.12; c83fa19603bdaeef17b815713dbbe3230c8a34ee <6809379a860b9fccbb5435bf08343f6d081ac68d; patch: 6.1.183; c83fa19603bdaeef17b815713dbbe3230c8a34ee <e2ab7e878bdbe80104c879c31fd2d82a476703b8
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.