PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74583 Linux CVE debrief

The Linux kernel has a use-after-free vulnerability in the route4 classifier fastmap. A race condition allows a reader to cache a pointer to a filter after it has been unlinked and freed by a writer. This can cause a KASAN slab-use-after-free report when a packet hits the stale fastmap entry. The vulnerability was introduced in the Linux kernel's route4 classifier fastmap. The route4 classifier maintains a 16-slot fastmap cache that stores raw struct route4_filter pointers indexed by (id, iif). A reproducer was provided using an mdelay(100) accelerator in route4_set_fastmap() and a concurrent add/delete stress test. Both triggered KASAN slab-use-after-free reports in the route4 fastmap paths. The fix introduces a per-filter boolean dying flag to suppress stale fastmap republishing by in-flight readers.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Linux kernel developers and administrators, network security teams, and organizations using Linux-based systems should review and apply the provided kernel patches to fix the vulnerability. They should also implement additional monitoring and logging to detect potential exploitation attempts and consider using a Web Application Firewall (WAF) to detect and prevent attacks. Regular vulnerability scans and patch management are crucial to ensure timely updates and mitigate potential risks. Affected Linux kernel deployments should be identified and prioritized for remediation based on their operational criticality and potential exposure to attacks. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory and vulnerability management processes should be reviewed to ensure that affected systems are properly identified and remediated. Monitoring and detection capabilities should be enhanced to identify potential exploitation attempts and anomalous behavior. Rollback and change management procedures should be implemented to quickly revert changes if issues arise during remediation. Source tracking and incident response planning are essential to quickly respond to potential security incidents related to this vulnerability. Compensating controls, such as network segmentation and access controls, may be necessary to mitigate risks while remediation is scheduled and verified. The Linux kernel community and relevant open-source projects should be engaged to ensure that the fix is properly integrated and tested. Collaboration with Linux distribution maintainers and cloud providers may be necessary to ensure that the fix is properly deployed and configured in various environments. The National Vulnerability Database (NVD) and other vulnerability management resources should be consulted to stay informed about potential risks and mitigation strategies. Security awareness and training programs should be updated to educate developers, administrators, and users about the risks associated with this vulnerability and the importance of timely remediation and mitigation. Business continuity and disaster-re覆盖

Technical summary

The route4 classifier maintains a 16-slot fastmap cache that stores raw struct route4_filter pointers indexed by (id, iif). A race condition allows a reader to cache a pointer to a filter after it has been unlinked and freed by a writer. The fix introduces a per-filter boolean dying flag to suppress stale fastmap republishing by in-flight readers. This change prevents the use-after-free vulnerability by ensuring that stale fastmap entries are not accessed after the filter has been freed.

Defensive priority

High

Recommended defensive actions

  • Review and apply the provided kernel patches to fix the vulnerability
  • Implement additional monitoring and logging to detect potential exploitation attempts
  • Consider using a Web Application Firewall (WAF) to detect and prevent attacks
  • Perform regular vulnerability scans and patch management to ensure timely updates
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability was introduced in the Linux kernel's route4 classifier fastmap. A reproducer was provided using an mdelay(100) accelerator in route4_set_fastmap() and a concurrent add/delete stress test. Both triggered KASAN slab-use-after-free reports in the route4 fastmap paths. The fix introduces a per-filter boolean dying flag to suppress stale fastmap republishing by in-flight readers. Evidence is limited to public CVE details and NVD information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-74583 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-74583

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-74583 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74583

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0e7a8cf8895b06d07c7311f028eba16ad742b9bc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/47d7f7051253bdc02b1d245d87e38f16d31a74df

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5ec9001be6d0eb527251125632ec8fe88278897f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7897198b26445b4009a057bda1986b94a99e5d5f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/820f083c294ad6d319c02a7d43294f2ed2565139

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a17f636c9330eac879822ce29f998e5abd1b72c1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ae9aff87025219005a2d16b4fe83d6f24643e50d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.