{"api_version":"1","generated_at":"2026-08-21T10:18:27+00:00","cve":"CVE-2026-74492","urls":{"html":"https://cve.report/CVE-2026-74492","api":"https://cve.report/api/cve/CVE-2026-74492.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74492","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74492"},"summary":{"title":"netfilter: ipset: do not update comments from kernel-side hash adds","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: do not update comments from kernel-side hash adds\n\nmtype_resize() copies comment pointers with memcpy(), not the comment\nobjects themselves. During the window after an entry has been copied but\nbefore the table swap and backlog replay, the old table is still\npublished for packet-side updates while the replacement-table entry\nalready holds the same ip_set_comment_rcu pointer.\n\nIf xt_SET --add-set ... --exist hits that old entry in this window,\nmtype_add() calls ip_set_init_comment() even though packet-side adds\ncarry no comment payload. That call frees the shared comment through the\nold entry, so the replacement-table entry now holds a stale pointer.\nWhen the queued add is replayed on the new table, mtype_add() calls\nip_set_init_comment() again and strlen() dereferences the stale pointer.\n\nFix this in mtype_add() by skipping ip_set_init_comment() when\next->target marks a packet-side add. Userspace adds still update\ncomments, while packet-side adds can no longer free comment storage\nshared with a resize copy.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 13:17:54","updated_at":"2026-08-19 17:21:06"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/77dbb248a5cc7a5270cd37bbb0b635bf059a872a","name":"https://git.kernel.org/stable/c/77dbb248a5cc7a5270cd37bbb0b635bf059a872a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4ae701848e4ba9e9713375fb7d82218cbd309da2","name":"https://git.kernel.org/stable/c/4ae701848e4ba9e9713375fb7d82218cbd309da2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f9d6cabff1fca010562dcdb0d22b296bdca3ba5a","name":"https://git.kernel.org/stable/c/f9d6cabff1fca010562dcdb0d22b296bdca3ba5a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/661ff9c0cfbe07f8eed920dde9f7781491738207","name":"https://git.kernel.org/stable/c/661ff9c0cfbe07f8eed920dde9f7781491738207","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f30415929be8aeb002d557c8d3f7ab2d2188003a","name":"https://git.kernel.org/stable/c/f30415929be8aeb002d557c8d3f7ab2d2188003a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/16bfa7be2d76ca1e0aacfa363482e1bf8ab5042a","name":"https://git.kernel.org/stable/c/16bfa7be2d76ca1e0aacfa363482e1bf8ab5042a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c710e9bf38e4e71a8db85d26a0f70c0674664207","name":"https://git.kernel.org/stable/c/c710e9bf38e4e71a8db85d26a0f70c0674664207","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6f13f4d52d06986c18f12e8bffaab944dd27ceab","name":"https://git.kernel.org/stable/c/6f13f4d52d06986c18f12e8bffaab944dd27ceab","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74492","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74492","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f66ee0410b1c3481ee75e5db9b34547b4d582465 6f13f4d52d06986c18f12e8bffaab944dd27ceab git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f66ee0410b1c3481ee75e5db9b34547b4d582465 f9d6cabff1fca010562dcdb0d22b296bdca3ba5a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f66ee0410b1c3481ee75e5db9b34547b4d582465 16bfa7be2d76ca1e0aacfa363482e1bf8ab5042a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f66ee0410b1c3481ee75e5db9b34547b4d582465 661ff9c0cfbe07f8eed920dde9f7781491738207 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f66ee0410b1c3481ee75e5db9b34547b4d582465 c710e9bf38e4e71a8db85d26a0f70c0674664207 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f66ee0410b1c3481ee75e5db9b34547b4d582465 4ae701848e4ba9e9713375fb7d82218cbd309da2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f66ee0410b1c3481ee75e5db9b34547b4d582465 77dbb248a5cc7a5270cd37bbb0b635bf059a872a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f66ee0410b1c3481ee75e5db9b34547b4d582465 f30415929be8aeb002d557c8d3f7ab2d2188003a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5dd9488ae41070b69d2f4acb580f77db5705f9ca git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a469bab3386aebff33c59506f3a95e35b91118fd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.4.24 5.5 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.5.8 5.6 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.6","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.6 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.265 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.216 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.183 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.151 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.103 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.44 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.8 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"74492","cve":"CVE-2026-74492","epss":"0.001420000","percentile":"0.039850000","score_date":"2026-08-19","updated_at":"2026-08-20 00:13:09"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/netfilter/ipset/ip_set_hash_gen.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"6f13f4d52d06986c18f12e8bffaab944dd27ceab","status":"affected","version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","versionType":"git"},{"lessThan":"f9d6cabff1fca010562dcdb0d22b296bdca3ba5a","status":"affected","version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","versionType":"git"},{"lessThan":"16bfa7be2d76ca1e0aacfa363482e1bf8ab5042a","status":"affected","version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","versionType":"git"},{"lessThan":"661ff9c0cfbe07f8eed920dde9f7781491738207","status":"affected","version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","versionType":"git"},{"lessThan":"c710e9bf38e4e71a8db85d26a0f70c0674664207","status":"affected","version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","versionType":"git"},{"lessThan":"4ae701848e4ba9e9713375fb7d82218cbd309da2","status":"affected","version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","versionType":"git"},{"lessThan":"77dbb248a5cc7a5270cd37bbb0b635bf059a872a","status":"affected","version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","versionType":"git"},{"lessThan":"f30415929be8aeb002d557c8d3f7ab2d2188003a","status":"affected","version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","versionType":"git"},{"status":"affected","version":"5dd9488ae41070b69d2f4acb580f77db5705f9ca","versionType":"git"},{"status":"affected","version":"a469bab3386aebff33c59506f3a95e35b91118fd","versionType":"git"},{"lessThan":"5.5","status":"affected","version":"5.4.24","versionType":"semver"},{"lessThan":"5.6","status":"affected","version":"5.5.8","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/netfilter/ipset/ip_set_hash_gen.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.6"},{"lessThan":"5.6","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.265","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.216","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.183","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.151","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.103","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.44","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.8","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.265","versionStartIncluding":"5.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.216","versionStartIncluding":"5.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.183","versionStartIncluding":"5.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.151","versionStartIncluding":"5.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.103","versionStartIncluding":"5.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.44","versionStartIncluding":"5.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.8","versionStartIncluding":"5.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"5.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.24","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5.8","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: do not update comments from kernel-side hash adds\n\nmtype_resize() copies comment pointers with memcpy(), not the comment\nobjects themselves. During the window after an entry has been copied but\nbefore the table swap and backlog replay, the old table is still\npublished for packet-side updates while the replacement-table entry\nalready holds the same ip_set_comment_rcu pointer.\n\nIf xt_SET --add-set ... --exist hits that old entry in this window,\nmtype_add() calls ip_set_init_comment() even though packet-side adds\ncarry no comment payload. That call frees the shared comment through the\nold entry, so the replacement-table entry now holds a stale pointer.\nWhen the queued add is replayed on the new table, mtype_add() calls\nip_set_init_comment() again and strlen() dereferences the stale pointer.\n\nFix this in mtype_add() by skipping ip_set_init_comment() when\next->target marks a packet-side add. Userspace adds still update\ncomments, while packet-side adds can no longer free comment storage\nshared with a resize copy."}],"metrics":[{"cvssV3_1":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached via the netfilter xt_SET packet path (set_target_* -> ip_set_add -> kadt -> mtype_add) during skb processing in iptables hooks; kernel CNA guidance treats netfilter/ipset as Local even when triggering packets arrive from the network.\nAC:L - An attacker can drive both sides of the resize race by filling a comment-enabled hash set and concurrently sending packets that hit SET --add-set --exist while mtype_resize() copies entries, making the shared-comment UAF window repeatable rather than dependent on uncontrollable timing.\nPR:N - Exploitation requires only sending traffic that matches an already-installed SET --exist rule on a comment-enabled ipset during resize; no local account or CAP_NET_ADMIN is needed, though unprivileged user namespaces can also obtain CAP_NET_ADMIN to configure the full attack chain.\nUI:N - Triggering is fully automatic through netfilter packet handling once the vulnerable ipset/iptables configuration exists; the attacker does not need the victim to click, mount, or perform any deliberate action beyond ordinary packet delivery.\nS:U - The flaw corrupts kernel heap memory and can yield host privilege escalation, but it does not cross a distinct security authority such as a VM/host, container/host, or IOMMU boundary; impact remains within the same kernel security domain.\nC:H - Packet-side mtype_add() frees a shared ip_set_comment_rcu during resize, leaving duplicate entries with dangling pointers; backlog replay calls ip_set_init_comment() and strlen() on freed kmalloc memory, a classic UAF that can disclose arbitrary kernel data with heap grooming.\nI:H - The UAF over RCU-freed comment objects lets an attacker reclaim and control freed slab memory, providing a standard path to arbitrary kernel writes, metadata corruption, and control-flow hijack rather than a bounded or crash-only integrity effect.\nA:H - Stale comment pointer dereference during resize backlog replay can immediately kernel-oops/panic the host, and the underlying UAF heap corruption can crash or hang the system even when full exploitation is not attempted."}]}],"providerMetadata":{"dateUpdated":"2026-08-19T16:37:48.078Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/6f13f4d52d06986c18f12e8bffaab944dd27ceab"},{"url":"https://git.kernel.org/stable/c/f9d6cabff1fca010562dcdb0d22b296bdca3ba5a"},{"url":"https://git.kernel.org/stable/c/16bfa7be2d76ca1e0aacfa363482e1bf8ab5042a"},{"url":"https://git.kernel.org/stable/c/661ff9c0cfbe07f8eed920dde9f7781491738207"},{"url":"https://git.kernel.org/stable/c/c710e9bf38e4e71a8db85d26a0f70c0674664207"},{"url":"https://git.kernel.org/stable/c/4ae701848e4ba9e9713375fb7d82218cbd309da2"},{"url":"https://git.kernel.org/stable/c/77dbb248a5cc7a5270cd37bbb0b635bf059a872a"},{"url":"https://git.kernel.org/stable/c/f30415929be8aeb002d557c8d3f7ab2d2188003a"}],"title":"netfilter: ipset: do not update comments from kernel-side hash adds","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-74492","datePublished":"2026-08-15T12:27:21.365Z","dateReserved":"2026-08-15T05:44:03.906Z","dateUpdated":"2026-08-19T16:37:48.078Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 13:17:54","lastModifiedDate":"2026-08-19 17:21:06","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74492","Ordinal":"1","Title":"netfilter: ipset: do not update comments from kernel-side hash a","CVE":"CVE-2026-74492","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74492","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: do not update comments from kernel-side hash adds\n\nmtype_resize() copies comment pointers with memcpy(), not the comment\nobjects themselves. During the window after an entry has been copied but\nbefore the table swap and backlog replay, the old table is still\npublished for packet-side updates while the replacement-table entry\nalready holds the same ip_set_comment_rcu pointer.\n\nIf xt_SET --add-set ... --exist hits that old entry in this window,\nmtype_add() calls ip_set_init_comment() even though packet-side adds\ncarry no comment payload. That call frees the shared comment through the\nold entry, so the replacement-table entry now holds a stale pointer.\nWhen the queued add is replayed on the new table, mtype_add() calls\nip_set_init_comment() again and strlen() dereferences the stale pointer.\n\nFix this in mtype_add() by skipping ip_set_init_comment() when\next->target marks a packet-side add. Userspace adds still update\ncomments, while packet-side adds can no longer free comment storage\nshared with a resize copy.","Type":"Description","Title":"netfilter: ipset: do not update comments from kernel-side hash a"}]}}}