From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-74288: net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
Date: Sat, 15 Aug 2026 15:10:15 +0900 [thread overview]
Message-ID: <2026081547-CVE-2026-74288-d92e@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
rocker_router_fib_event() calls fib_rule_get() during RCU dump.
If the fib_rule is dying, refcount_inc() will complain about it.
Let's call refcount_inc_not_zero() in fib_rules_dump().
The Linux kernel CVE team has assigned CVE-2026-74288 to this issue.
Affected and fixed versions
===========================
Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 5.10.261 with commit 0f929b59f4cd0e05bb1ecefe12b77e85911d4be2
Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 5.15.212 with commit 4b7ae30c81c2ee10a644749a3704a5c797ccc308
Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 6.1.178 with commit 2dfdc210d240bd48bb2ea746430b02b5571b6db9
Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 6.6.145 with commit a7ef30753353ba6a95d693b1863a0214222a199a
Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 6.12.97 with commit 1fbc6c6efe78f4454a51afa0587efb6826f60f00
Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 6.18.40 with commit bb4a5b3c91af3c8d705bb2e9f6f8069a70db26fc
Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 7.1.5 with commit 3af0bc1bd9039e2e50abf3e2d7fee411f38bce4e
Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 7.2-rc1 with commit 2821e85c058f81c9948a2fb1a634f7b47457d51c
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-74288
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
include/net/fib_rules.h
net/core/fib_rules.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/0f929b59f4cd0e05bb1ecefe12b77e85911d4be2
https://git.kernel.org/stable/c/4b7ae30c81c2ee10a644749a3704a5c797ccc308
https://git.kernel.org/stable/c/2dfdc210d240bd48bb2ea746430b02b5571b6db9
https://git.kernel.org/stable/c/a7ef30753353ba6a95d693b1863a0214222a199a
https://git.kernel.org/stable/c/1fbc6c6efe78f4454a51afa0587efb6826f60f00
https://git.kernel.org/stable/c/bb4a5b3c91af3c8d705bb2e9f6f8069a70db26fc
https://git.kernel.org/stable/c/3af0bc1bd9039e2e50abf3e2d7fee411f38bce4e
https://git.kernel.org/stable/c/2821e85c058f81c9948a2fb1a634f7b47457d51c
reply other threads:[~2026-08-15 6:33 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026081547-CVE-2026-74288-d92e@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox