From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 97CE83803DB for ; Sat, 15 Aug 2026 06:33:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786775598; cv=none; b=Q3MguXsTf046rBdmv6whLwDvBGL4NaojLk36V7vcGd/0BulJpqS+c49J3MNp7ggMppNwPq5fl5ldD7mWdU8pRQgdbPPmgPfpW2ZhmDEhlX6EJoobYMyu/0QVOaMP5IduUqnrxaBmwPeTZP/37BXOAvKA5Qt5G985/KGoPCMsAuc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786775598; c=relaxed/simple; bh=XsVdmgNmh0eOAf5AQA4ZqAQNw7ZcYueiZO2awkTL1xE=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=N8sMl9jtgreeRXqCsAB2QMP4b3CnZOno8zTq3lLurNHANp+LAUyK0wiJUiYHL0MkfF+LBamCGv1xifIg+z+AJbHS9tBO27KSwNUPJ1miSN7qRR8MdZy4ZfQb8Y8U8oVTdykNVHglmEA45BDc63I0md7/4Mt+0xbTf4rw1z15IHw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=qx445MEr; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="qx445MEr" Received: by smtp.kernel.org (Postfix) with ESMTPSA id A1D901F000E9; Sat, 15 Aug 2026 06:33:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786775597; bh=Eot3ER5WZ3X7XYHSwpmEj2nlmge8Ev7XZTBsPKLJeyE=; h=From:To:Cc:Subject:Date:Reply-To; b=qx445MEroaOmFbjxiFi89sermhVf2rLlFNFo9ActlLSbgOxvljHYGGocCywTgJ+n2 Os7dQvCjEKr83zip75Af9MoAuS7u/XVM2kfJfBmrTNuBUPbSz/7tj4co1Davoh1AXi PvoFIJeaT2BaNkhRc+N69F7laweKYf97/+K+xS8E= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-74288: net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). Date: Sat, 15 Aug 2026 15:10:15 +0900 Message-ID: <2026081547-CVE-2026-74288-d92e@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3360; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=9m39ysAHtsyG6+qRD2Bm4s16yv8Wxfwj6wNpsIdgZU8=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkNjOwHD8832KBjE6q97pWS8oWLDwu3HN0s/zZAxDR0Q q6+vWJpRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAExkBivD/OzXrf/q+oSE2sKn H3U6XLC5WVjyGsNstqWJW5eaHytYJf30vNbPAx1XW9qvAwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). rocker_router_fib_event() calls fib_rule_get() during RCU dump. If the fib_rule is dying, refcount_inc() will complain about it. Let's call refcount_inc_not_zero() in fib_rules_dump(). The Linux kernel CVE team has assigned CVE-2026-74288 to this issue. Affected and fixed versions =========================== Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 5.10.261 with commit 0f929b59f4cd0e05bb1ecefe12b77e85911d4be2 Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 5.15.212 with commit 4b7ae30c81c2ee10a644749a3704a5c797ccc308 Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 6.1.178 with commit 2dfdc210d240bd48bb2ea746430b02b5571b6db9 Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 6.6.145 with commit a7ef30753353ba6a95d693b1863a0214222a199a Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 6.12.97 with commit 1fbc6c6efe78f4454a51afa0587efb6826f60f00 Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 6.18.40 with commit bb4a5b3c91af3c8d705bb2e9f6f8069a70db26fc Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 7.1.5 with commit 3af0bc1bd9039e2e50abf3e2d7fee411f38bce4e Issue introduced in 4.12 with commit 5d7bfd141924a5ece21eb612ad3c56612f041c1e and fixed in 7.2-rc1 with commit 2821e85c058f81c9948a2fb1a634f7b47457d51c Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74288 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: include/net/fib_rules.h net/core/fib_rules.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/0f929b59f4cd0e05bb1ecefe12b77e85911d4be2 https://git.kernel.org/stable/c/4b7ae30c81c2ee10a644749a3704a5c797ccc308 https://git.kernel.org/stable/c/2dfdc210d240bd48bb2ea746430b02b5571b6db9 https://git.kernel.org/stable/c/a7ef30753353ba6a95d693b1863a0214222a199a https://git.kernel.org/stable/c/1fbc6c6efe78f4454a51afa0587efb6826f60f00 https://git.kernel.org/stable/c/bb4a5b3c91af3c8d705bb2e9f6f8069a70db26fc https://git.kernel.org/stable/c/3af0bc1bd9039e2e50abf3e2d7fee411f38bce4e https://git.kernel.org/stable/c/2821e85c058f81c9948a2fb1a634f7b47457d51c