Junglewise Threat Intelligence

CVE-2026-74583: Linux kernel route4 classifier use-after-free in fastmap

CVE-2026-74583 · Severity: high · CVSS 7.8 · Published 2026-08-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's traffic classification system for packet routing contains a race condition in its cache mechanism that can cause the system to access freed memory. When network packets are being classified and cached simultaneously with filter rule updates, an attacker with local network access could trigger a kernel crash or potentially execute code, disrupting network operations.

Technical details

A use-after-free vulnerability exists in net/sched/cls_route.c where the route4 classifier's 16-slot fastmap cache stores pointers to filter objects. The race occurs between cache readers (route4_classify) and writers (route4_delete, route4_change): a reader can populate the cache with a filter pointer after the writer has reset the cache but before the RCU grace period and kfree() execute, resulting in a stale pointer. On subsequent packet classification with the same (id, iif) tuple, dereferencing this freed filter structure causes a use-after-free. The vulnerability is network-reachable and requires only the ability to trigger concurrent packet classification and filter updates. The fix introduces a per-filter "dying" flag checked under spinlock during fastmap writes to suppress stale republishing by in-flight readers.

Affected products

  • Linux Linux kernel affected versions not explicitly specified in advisory; patch available in stable tree

Timeline

  • 2026-08-21: disclosed: CVE-2026-74583 published
  • 2026-07-31: patched: Upstream fix committed by Jakub Kicinski
  • 2026-08-19: patched: Fix included in stable kernel tree

References

Related threats