CVE-2026-74748
CVE CVE-2026-74748EUVD EUVD-2026-66578Published 2026-08-26T14:36:57.000ZLast changed 2026-08-27T05:01:09.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix refcount race between list:set GC and swap __ip_set_put_byindex() resolved the index to a set pointer under RCU, then took ip_set_ref_lock in __ip_set_put() to decrement set->ref. ip_set_swap() holds that same lock while swapping both the ip_set_list slots and the two sets' ref counters, so it can interleave between the dereference and the lock acquisition, leaving the caller to decrement a set whose reference already moved to the other index and hit BUG_ON(set->ref == 0). list_set_gc() reaches this from timer softirq, which the nfnl mutex does not serialize against swap: an expiring list:set member calls list_set_del() -> ip_set_put_byindex() while IPSET_CMD_SWAP runs on the referenced sets. Resolve the index and decrement under ip_set_ref_lock, as ip_set_swap() already does, keeping the refcount tied to the index rather than to a stale set pointer. kernel BUG at net/netfilter/ipset/ip_set_core.c:685! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:ip_set_put_byindex (net/netfilter/ipset/ip_set_core.c:870) Call Trace: <IRQ> list_set_del (net/netfilter/ipset/ip_set_list_set.c:159) set_cleanup_entries (net/netfilter/ipset/ip_set_list_set.c:181) list_set_gc (net/netfilter/ipset/ip_set_list_set.c:578) call_timer_fn (kernel/time/timer.c:1748) __run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2374) run_timer_softirq (kernel/time/timer.c:2405) </IRQ> Kernel panic - not syncing: Fatal exception in interrupt
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.2; 9076aea76538556224e7d73ab718f8841330818a <97a01de0c6321b7210d30d0a4d60f10f561097c7; patch: 6.1.184; patch: 6.18.46; patch: 7.1.10; 9076aea76538556224e7d73ab718f8841330818a <cb20da33839f28f590c99f16bafaa6151451c0e8; 9076aea76538556224e7d73ab718f8841330818a <20cb13a523f0a05cb2d0a7d72abae687683712e0; 9076aea76538556224e7d73ab718f8841330818a <c21afc7c216a4d257a4f3f300e0791890bc846b9; 9076aea76538556224e7d73ab718f8841330818a <b891e7a6bb06e0f6560e5932665ac660acd12225; patch: 5.15.217; patch: 6.6.153; patch: 6.12.105; 9076aea76538556224e7d73ab718f8841330818a <b0aab9dd1a348b99d75ff52765719d0cc2050630; 3.8; 9076aea76538556224e7d73ab718f8841330818a <0c88868271653537ed443272dd8e7d13634d214b; patch: 0; patch: 5.10.266; 9076aea76538556224e7d73ab718f8841330818a <24ffcb1e1688c55fd2a505f064295cd28eac546d
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.