Executive brief
The Linux kernel's networking subsystem contains a vulnerability in its Forwarding Information Base (FIB) rules handling that can lead to a denial of service or system crash. When the kernel attempts to dump FIB rules during certain network operations, it may try to reference a rule that is in the process of being deleted, causing a reference counting error. An attacker with local network access could potentially trigger this condition to crash the system or cause network services to become unavailable.
Technical details
The vulnerability is a use-after-free issue in the net/core/fib_rules.c module's fib_rules_dump() function. When dumping FIB rules to notify registered listeners of rule additions, the kernel iterates through the rules list under RCU protection. However, it uses refcount_inc() directly on rules that may be in the process of being deleted (dying state). If a rule's refcount has already been decremented to zero, refcount_inc() will fail and generate a kernel warning. The fix introduces fib_rule_get_safe() which uses refcount_inc_not_zero() to safely skip rules that are actively being deleted. This prevents kernel panics and reference count violations. The vulnerability requires local access to trigger networking operations that cause FIB rule dumps.
Affected products
- Linux Linux kernel 5.0 through at least 7.2
Timeline
- 2026-08-15: disclosed: CVE-2026-74288 published
- 2026-06-10: patched: Fix committed upstream by Kuniyuki Iwashima
- 2026-07-24: other: Fix merged into stable kernel trees