Linux kernel CVE announcements
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-74288: net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
Date: Sat, 15 Aug 2026 15:10:15 +0900	[thread overview]
Message-ID: <2026081547-CVE-2026-74288-d92e@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().

rocker_router_fib_event() calls fib_rule_get() during RCU dump.

If the fib_rule is dying, refcount_inc() will complain about it.

Let's call refcount_inc_not_zero() in fib_rules_dump().

The Linux kernel CVE team has assigned CVE-2026-74288 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 5.10.261 with commit 0f929b59f4cd0e05bb1ecefe12b77e85911d4be2
	Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 5.15.212 with commit 4b7ae30c81c2ee10a644749a3704a5c797ccc308
	Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 6.1.178 with commit 2dfdc210d240bd48bb2ea746430b02b5571b6db9
	Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 6.6.145 with commit a7ef30753353ba6a95d693b1863a0214222a199a
	Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 6.12.97 with commit 1fbc6c6efe78f4454a51afa0587efb6826f60f00
	Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 6.18.40 with commit bb4a5b3c91af3c8d705bb2e9f6f8069a70db26fc
	Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 7.1.5 with commit 3af0bc1bd9039e2e50abf3e2d7fee411f38bce4e
	Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 7.2-rc1 with commit 2821e85c058f81c9948a2fb1a634f7b47457d51c

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-74288
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	include/net/fib_rules.h
	net/core/fib_rules.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/0f929b59f4cd0e05bb1ecefe12b77e85911d4be2
	https://git.kernel.org/stable/c/4b7ae30c81c2ee10a644749a3704a5c797ccc308
	https://git.kernel.org/stable/c/2dfdc210d240bd48bb2ea746430b02b5571b6db9
	https://git.kernel.org/stable/c/a7ef30753353ba6a95d693b1863a0214222a199a
	https://git.kernel.org/stable/c/1fbc6c6efe78f4454a51afa0587efb6826f60f00
	https://git.kernel.org/stable/c/bb4a5b3c91af3c8d705bb2e9f6f8069a70db26fc
	https://git.kernel.org/stable/c/3af0bc1bd9039e2e50abf3e2d7fee411f38bce4e
	https://git.kernel.org/stable/c/2821e85c058f81c9948a2fb1a634f7b47457d51c

                 reply	other threads:[~2026-08-15  6:33 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026081547-CVE-2026-74288-d92e@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox