CVE-2026-74661
In the Linux kernel, the following vulnerability has been resolved:
mac802154: fix netdev use-after-free in beacon worker
mac802154_beacon_worker() reads local->beacon_req under RCU and derives the sub-interface from the request, but then drops the RCU read lock and continues to use both sdata and the embedded wpan_dev.
mac802154_stop_beacons_locked() cancels only pending beacon work, clears local->beacon_req and frees the request. A beacon worker that is already running can therefore continue after interface teardown and dereference the freed netdev private area.
The scan worker already pins the netdev before leaving RCU. Apply the same lifetime rule to the beacon worker: take a netdev reference while the request is still protected by RCU, and release it on all paths that continue after the reference is acquired.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact75 % - Impacto secundario
T1565.001Stored Data Manipulationimpact60 %
Vulnerabilidad local de use-after-free en kernel Linux (AV:L, PR:L) permitiendo DoS por crash de netdev y potencial corrupción de memoria tras liberación. Acceso local sin interacción del usuario.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/5f26a690e8efa54315e4922368daf54e0b8f5515
- https://git.kernel.org/stable/c/9d067e581597c462c51fee8a30b51bc48a68c4e1
- https://git.kernel.org/stable/c/e5fb0e03bc7f45508c182a427357bf6b389a9033
- https://git.kernel.org/stable/c/e6cd416a899edc912b428c4ba399bd73f516cb31
- https://git.kernel.org/stable/c/fe820dcc1d8ff77783a9d2bcc93b98c99ac6d517
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74661",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3accf4762734a69ebd03cba989249c78ac7dfc7e",
"lessThan": "fe820dcc1d8ff77783a9d2bcc93b98c99ac6d517",
"versionType": "git"
},
{
"status": "affected",
"version": "3accf4762734a69ebd03cba989249c78ac7dfc7e",
"lessThan": "e5fb0e03bc7f45508c182a427357bf6b389a9033",
"versionType": "git"
},
{
"status": "affected",
"version": "3accf4762734a69ebd03cba989249c78ac7dfc7e",
"lessThan": "e6cd416a899edc912b428c4ba399bd73f516cb31",
"versionType": "git"
},
{
"status": "affected",
"version": "3accf4762734a69ebd03cba989249c78ac7dfc7e",
"lessThan": "9d067e581597c462c51fee8a30b51bc48a68c4e1",
"versionType": "git"
},
{
"status": "affected",
"version": "3accf4762734a69ebd03cba989249c78ac7dfc7e",
"lessThan": "5f26a690e8efa54315e4922368daf54e0b8f5515",
"versionType": "git"
}
],
"programFiles": [
"net/mac802154/scan.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/mac802154/scan.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-22T16:16:39.883",
"references": [
{
"url": "https://git.kernel.org/stable/c/5f26a690e8efa54315e4922368daf54e0b8f5515",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9d067e581597c462c51fee8a30b51bc48a68c4e1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e5fb0e03bc7f45508c182a427357bf6b389a9033",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e6cd416a899edc912b428c4ba399bd73f516cb31",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fe820dcc1d8ff77783a9d2bcc93b98c99ac6d517",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac802154: fix netdev use-after-free in beacon worker\n\nmac802154_beacon_worker() reads local->beacon_req under RCU and derives\nthe sub-interface from the request, but then drops the RCU read lock and\ncontinues to use both sdata and the embedded wpan_dev.\n\nmac802154_stop_beacons_locked() cancels only pending beacon work, clears\nlocal->beacon_req and frees the request. A beacon worker that is already\nrunning can therefore continue after interface teardown and dereference\nthe freed netdev private area.\n\nThe scan worker already pins the netdev before leaving RCU. Apply the\nsame lifetime rule to the beacon worker: take a netdev reference while\nthe request is still protected by RCU, and release it on all paths that\ncontinue after the reference is acquired."
}
],
"lastModified": "2026-08-25T06:18:47.263",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}