CVE-2026-74744
In the Linux kernel, the following vulnerability has been resolved:
ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(), but leave needed_headroom and needed_tailroom set to 0.
When the underlying phy_dev (or stacked lower device) requires extra headroom or tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx headroom), upper layers calculating packet headroom and tailroom fail to reserve sufficient space.
This can result in reallocation overhead, skb headroom underflows, or KASAN slab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header() prepends header data or when lower devices append tailroom.
Leer descripción completaMostrar menos
Fix this by: 1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init(). 2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.70%
- Percentil entre todas las CVEs puntuadas: 52
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto principal
T1499.004Application or System Exploitationimpact65 %
Vulnerabilidad remota de red (AV:N, PR:N, UI:N) en kernel Linux que causa crashes KASAN y corrupción de memoria por fallo de reserva de espacio en paquetes, permitiendo DoS o manipulación de datos en tráfico.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/5c2ca77212eb38559b0353b8363b7a84f4b019dd
- https://git.kernel.org/stable/c/5f33188457bbcc1b11ca87084037963c516ed3d9
- https://git.kernel.org/stable/c/af602c4d0ee548da18e2409b4b4da1079625a372
- https://git.kernel.org/stable/c/c0fbe31f6b20ade0465130685859faa5c86fda59
- https://git.kernel.org/stable/c/e16e960d55a40d36bd7c2494cc005e757dc9a1ef
- https://git.kernel.org/stable/c/f3c17ff65f54781cde696e16a6c577615ed735aa
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74744",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2ad7bf3638411cb547f2823df08166c13ab04269",
"lessThan": "af602c4d0ee548da18e2409b4b4da1079625a372",
"versionType": "git"
},
{
"status": "affected",
"version": "2ad7bf3638411cb547f2823df08166c13ab04269",
"lessThan": "f3c17ff65f54781cde696e16a6c577615ed735aa",
"versionType": "git"
},
{
"status": "affected",
"version": "2ad7bf3638411cb547f2823df08166c13ab04269",
"lessThan": "c0fbe31f6b20ade0465130685859faa5c86fda59",
"versionType": "git"
},
{
"status": "affected",
"version": "2ad7bf3638411cb547f2823df08166c13ab04269",
"lessThan": "5f33188457bbcc1b11ca87084037963c516ed3d9",
"versionType": "git"
},
{
"status": "affected",
"version": "2ad7bf3638411cb547f2823df08166c13ab04269",
"lessThan": "5c2ca77212eb38559b0353b8363b7a84f4b019dd",
"versionType": "git"
},
{
"status": "affected",
"version": "2ad7bf3638411cb547f2823df08166c13ab04269",
"lessThan": "e16e960d55a40d36bd7c2494cc005e757dc9a1ef",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/ipvlan/ipvlan_main.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ipvlan/ipvlan_main.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-26T15:16:53.250",
"references": [
{
"url": "https://git.kernel.org/stable/c/5c2ca77212eb38559b0353b8363b7a84f4b019dd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5f33188457bbcc1b11ca87084037963c516ed3d9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/af602c4d0ee548da18e2409b4b4da1079625a372",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c0fbe31f6b20ade0465130685859faa5c86fda59",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e16e960d55a40d36bd7c2494cc005e757dc9a1ef",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f3c17ff65f54781cde696e16a6c577615ed735aa",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvlan: inherit needed_headroom and needed_tailroom from phy_dev\n\nipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),\nbut leave needed_headroom and needed_tailroom set to 0.\n\nWhen the underlying phy_dev (or stacked lower device) requires extra headroom\nor tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or\nveth with rx headroom), upper layers calculating packet headroom and tailroom\nfail to reserve sufficient space.\n\nThis can result in reallocation overhead, skb headroom underflows, or KASAN\nslab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header()\nprepends header data or when lower devices append tailroom.\n\nFix this by:\n1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init().\n2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans\n in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events."
}
],
"lastModified": "2026-08-27T06:17:24.440",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}