CVE-2026-74708
In the Linux kernel, the following vulnerability has been resolved:
xsk: validate launch-time metadata size
Launch-time metadata extends beyond the first 16 bytes of struct xsk_tx_metadata. Reject the request when the registered metadata area does not contain the complete field.
Snapshot the validated flags for the generic transmit path and use that snapshot for request and completion processing, avoiding inconsistent decisions if user space changes the flags concurrently.
Note that only xsk_skb_metadata is properly using the flags, __xsk_buff_get_metadata ignores them. Next commits address that.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1059Command and Scripting Interpreterexecution75 % - Impacto secundario
T1499.004Application or System Exploitationimpact60 %
Vulnerabilidad local (AV:L, PR:L) sin interacción. Fallo de validación de metadatos en AF_XDP permite ejecutar código o causar DoS. Confirma escalada de privilegios.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74708",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "ca4419f15abd19ba8be1e109661b60f9f5b6c9f0",
"lessThan": "af511afa1d2977f384044df78d6fbf9fba653f7a",
"versionType": "git"
},
{
"status": "affected",
"version": "ca4419f15abd19ba8be1e109661b60f9f5b6c9f0",
"lessThan": "bc63d47611c07b0d5d655fe1a590861931527920",
"versionType": "git"
},
{
"status": "affected",
"version": "ca4419f15abd19ba8be1e109661b60f9f5b6c9f0",
"lessThan": "439ce2dddf3d22129b9113a7881637256a35e936",
"versionType": "git"
},
{
"status": "affected",
"version": "d9d736c416c9a85f84e15435ba82a177262e745b",
"versionType": "git"
},
{
"status": "affected",
"version": "6.14.2",
"lessThan": "6.15",
"versionType": "semver"
}
],
"programFiles": [
"include/net/xdp_sock_drv.h",
"net/xdp/xsk.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"include/net/xdp_sock_drv.h",
"net/xdp/xsk.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-22T16:16:45.540",
"references": [
{
"url": "https://git.kernel.org/stable/c/439ce2dddf3d22129b9113a7881637256a35e936",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/af511afa1d2977f384044df78d6fbf9fba653f7a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bc63d47611c07b0d5d655fe1a590861931527920",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: validate launch-time metadata size\n\nLaunch-time metadata extends beyond the first 16 bytes of struct\nxsk_tx_metadata. Reject the request when the registered metadata area does\nnot contain the complete field.\n\nSnapshot the validated flags for the generic transmit path and use that\nsnapshot for request and completion processing, avoiding inconsistent\ndecisions if user space changes the flags concurrently.\n\nNote that only xsk_skb_metadata is properly using the flags,\n__xsk_buff_get_metadata ignores them. Next commits address that."
}
],
"lastModified": "2026-08-25T06:18:55.453",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}