udp: fix potential use-after-free in tunnel segmentation

Summary

CVECVE-2026-74705
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-22 16:16:45 UTC
Updated2026-08-22 16:16:45 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP header before ensuring the tunnel header is in the skb head. If the pull reallocates skb->head, the saved UDP header pointer is no longer valid. Get the UDP header after the pull to avoid a potential use-after-free.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected dbef491ebe7f3a4fb1b9111878b86a426fd540b7 6a733a38b983d8c2e222f13968209010cf44de87 git Not specified
CNA Linux Linux affected dbef491ebe7f3a4fb1b9111878b86a426fd540b7 19d89b13a43640b2da2f277ee462d919d988cb6f git Not specified
CNA Linux Linux affected dbef491ebe7f3a4fb1b9111878b86a426fd540b7 b3df61bb745eb5201eac22679a2839d4ccbf3442 git Not specified
CNA Linux Linux affected dbef491ebe7f3a4fb1b9111878b86a426fd540b7 1ae134c012e10384cdac420b5cc6e0615cde0b55 git Not specified
CNA Linux Linux affected dbef491ebe7f3a4fb1b9111878b86a426fd540b7 5161e67c561c4f28a5d9335a6e859b02511de92b git Not specified
CNA Linux Linux affected dbef491ebe7f3a4fb1b9111878b86a426fd540b7 64d322c288577793eedd352b96ef75234ed380fe git Not specified
CNA Linux Linux affected dbef491ebe7f3a4fb1b9111878b86a426fd540b7 588d4a6795d99d080f74ef0b5f391ea8c453ae5d git Not specified
CNA Linux Linux affected dbef491ebe7f3a4fb1b9111878b86a426fd540b7 d0f86fb36eb260abd10007b62c9dcc1028e03e61 git Not specified
CNA Linux Linux affected 4.6 Not specified
CNA Linux Linux unaffected 4.6 semver Not specified
CNA Linux Linux unaffected 5.10.265 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.216 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.183 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.152 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.104 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.45 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.9 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/1ae134c012e10384cdac420b5cc6e0615cde0b55 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/64d322c288577793eedd352b96ef75234ed380fe 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/588d4a6795d99d080f74ef0b5f391ea8c453ae5d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/5161e67c561c4f28a5d9335a6e859b02511de92b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d0f86fb36eb260abd10007b62c9dcc1028e03e61 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6a733a38b983d8c2e222f13968209010cf44de87 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/19d89b13a43640b2da2f277ee462d919d988cb6f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b3df61bb745eb5201eac22679a2839d4ccbf3442 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report