Junglewise Threat Intelligence

CVE-2026-74670: Linux kernel IPVS estimator buffer overflow

CVE-2026-74670 · Severity: high · CVSS 7.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's IP Virtual Server (IPVS) module contains a buffer overflow vulnerability in its network traffic estimation subsystem. When the IPVS module is disabled during initialization of its estimator threads, uninitialized limit values can cause the threads to write beyond the bounds of internal array buffers. An attacker with local access could trigger this condition to crash the system or potentially execute arbitrary kernel code.

Technical details

The vulnerability exists in the IPVS estimator kthread (net/netfilter/ipvs/ip_vs_est.c) where thread-local limit values (chain_max, tick_max, est_max_count) remain zeroed if the calculation phase completes while IPVS is disabled. The kthread then continues into its main loop and processes temporary estimator entries, consuming tick rows without bounds. After all available rows are exhausted, the row lookup returns an out-of-bounds index (IPVS_EST_NTICKS), causing ip_vs_enqueue_estimator() to write past the ticks and tick_len array boundaries. The fix adds an early exit check after the calc phase and uses get_task_struct()/kthread_stop_put() to safely manage kthread lifecycle during namespace teardown. Local attack vector; requires ability to manage network namespaces or trigger IPVS disable during module initialization.

Affected products

  • Linux Linux kernel Multiple versions (affected versions include at least 4.x through 7.x based on stable tree references)

Timeline

  • 2026-08-22: disclosed
  • 2026-07-31: patched: Upstream fix committed; backported to stable kernels

References

Related threats