PatchSiren cyber security CVE debrief
CVE-2026-74289 Linux CVE debrief
CVE-2026-74289 is a use-after-free vulnerability in the Linux kernel's IPv4 FIB (Forwarding Information Base) code. The vulnerability arises from the fib_leaf_notify() function not properly guaranteeing the lifetime of fib_info structures while dumping them under RCU (Read-Copy-Update). This can lead to use-after-free conditions when functions like mlxsw_sp_router_fib4_event(), rocker_router_fib_event(), and nsim_fib4_prepare_event() call fib_info_hold() or refcount_inc() while dumping fib_info. To address this, the Linux kernel developers have resolved the issue by ensuring the lifetime of fib_info in fib_leaf_notify().
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for Linux kernel-based systems, particularly those using IPv4 FIB, should assess their exposure and prioritize patching. System administrators and security teams should verify and apply patches, monitor for exploitation attempts, and implement compensating controls to mitigate the risk.
Why it matters
CVE-2026-74289 is a use-after-free vulnerability in the Linux kernel's IPv4 FIB code. Defenders should prioritize verifying and applying patches, monitoring for exploitation attempts, and implementing compensating controls to mitigate the risk.
- Defenders need to verify and apply patches to prevent potential use-after-free conditions in the Linux kernel's IPv4 FIB code.
- System administrators should monitor for potential exploitation attempts and implement compensating controls to mitigate the risk.
- Security teams should prioritize patching Linux kernel versions affected by this vulnerability.
Technical summary
The Linux kernel's IPv4 FIB code has a use-after-free vulnerability. The fib_leaf_notify() function does not properly guarantee the lifetime of fib_info structures while dumping them under RCU. Functions like mlxsw_sp_router_fib4_event(), rocker_router_fib_event(), and nsim_fib4_prepare_event() call fib_info_hold() or refcount_inc() while dumping fib_info, leading to potential use-after-free conditions. The issue has been resolved by ensuring the lifetime of fib_info in fib_leaf_notify().
Defensive priority
Defenders should prioritize verifying and applying patches for Linux kernel versions affected by this vulnerability. They should also monitor for potential exploitation attempts and implement compensating controls to mitigate the risk.
Recommended defensive actions
- Verify and apply patches for Linux kernel versions affected by this vulnerability.
- Monitor for potential exploitation attempts.
- Implement compensating controls to mitigate the risk.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and associated source references provide details on the vulnerability, including its description, affected components, and fixed versions. However, specific versions of the Linux kernel that are affected or fixed have not been explicitly stated in the provided corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-74289 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-74289
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-74289 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74289
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/06b693d2eb6651a63ad85bad8673de3b7d4edd6d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/676482da8d938ea72c26da0fc86af2d2ec238ab2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7907a395701b339c2d68f37456d395e953c74795
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7980a13add57f97c5da1dc961d0145a6ad2a7f98
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8bdb20b8a581495062b5879f4e9d435da648b3b0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/bea03e887db5a8a79234531faf14cf2c4d8816c3
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.