{"api_version":"1","generated_at":"2026-08-28T00:32:00+00:00","cve":"CVE-2026-74744","urls":{"html":"https://cve.report/CVE-2026-74744","api":"https://cve.report/api/cve/CVE-2026-74744.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74744","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74744"},"summary":{"title":"ipvlan: inherit needed_headroom and needed_tailroom from phy_dev","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvlan: inherit needed_headroom and needed_tailroom from phy_dev\n\nipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),\nbut leave needed_headroom and needed_tailroom set to 0.\n\nWhen the underlying phy_dev (or stacked lower device) requires extra headroom\nor tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or\nveth with rx headroom), upper layers calculating packet headroom and tailroom\nfail to reserve sufficient space.\n\nThis can result in reallocation overhead, skb headroom underflows, or KASAN\nslab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header()\nprepends header data or when lower devices append tailroom.\n\nFix this by:\n1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init().\n2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans\n   in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-26 15:16:53","updated_at":"2026-08-27 06:17:24"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/5f33188457bbcc1b11ca87084037963c516ed3d9","name":"https://git.kernel.org/stable/c/5f33188457bbcc1b11ca87084037963c516ed3d9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c0fbe31f6b20ade0465130685859faa5c86fda59","name":"https://git.kernel.org/stable/c/c0fbe31f6b20ade0465130685859faa5c86fda59","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f3c17ff65f54781cde696e16a6c577615ed735aa","name":"https://git.kernel.org/stable/c/f3c17ff65f54781cde696e16a6c577615ed735aa","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/af602c4d0ee548da18e2409b4b4da1079625a372","name":"https://git.kernel.org/stable/c/af602c4d0ee548da18e2409b4b4da1079625a372","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5c2ca77212eb38559b0353b8363b7a84f4b019dd","name":"https://git.kernel.org/stable/c/5c2ca77212eb38559b0353b8363b7a84f4b019dd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e16e960d55a40d36bd7c2494cc005e757dc9a1ef","name":"https://git.kernel.org/stable/c/e16e960d55a40d36bd7c2494cc005e757dc9a1ef","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74744","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74744","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2ad7bf3638411cb547f2823df08166c13ab04269 af602c4d0ee548da18e2409b4b4da1079625a372 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2ad7bf3638411cb547f2823df08166c13ab04269 f3c17ff65f54781cde696e16a6c577615ed735aa git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2ad7bf3638411cb547f2823df08166c13ab04269 c0fbe31f6b20ade0465130685859faa5c86fda59 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2ad7bf3638411cb547f2823df08166c13ab04269 5f33188457bbcc1b11ca87084037963c516ed3d9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2ad7bf3638411cb547f2823df08166c13ab04269 5c2ca77212eb38559b0353b8363b7a84f4b019dd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2ad7bf3638411cb547f2823df08166c13ab04269 e16e960d55a40d36bd7c2494cc005e757dc9a1ef git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.19","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 3.19 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.184 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.153 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.105 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.46 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.10 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"74744","cve":"CVE-2026-74744","epss":"0.005190000","percentile":"0.419190000","score_date":"2026-08-27","updated_at":"2026-08-28 00:03:39"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/ipvlan/ipvlan_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"af602c4d0ee548da18e2409b4b4da1079625a372","status":"affected","version":"2ad7bf3638411cb547f2823df08166c13ab04269","versionType":"git"},{"lessThan":"f3c17ff65f54781cde696e16a6c577615ed735aa","status":"affected","version":"2ad7bf3638411cb547f2823df08166c13ab04269","versionType":"git"},{"lessThan":"c0fbe31f6b20ade0465130685859faa5c86fda59","status":"affected","version":"2ad7bf3638411cb547f2823df08166c13ab04269","versionType":"git"},{"lessThan":"5f33188457bbcc1b11ca87084037963c516ed3d9","status":"affected","version":"2ad7bf3638411cb547f2823df08166c13ab04269","versionType":"git"},{"lessThan":"5c2ca77212eb38559b0353b8363b7a84f4b019dd","status":"affected","version":"2ad7bf3638411cb547f2823df08166c13ab04269","versionType":"git"},{"lessThan":"e16e960d55a40d36bd7c2494cc005e757dc9a1ef","status":"affected","version":"2ad7bf3638411cb547f2823df08166c13ab04269","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/ipvlan/ipvlan_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"3.19"},{"lessThan":"3.19","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.184","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.153","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.105","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.46","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.10","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.184","versionStartIncluding":"3.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.153","versionStartIncluding":"3.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.105","versionStartIncluding":"3.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.46","versionStartIncluding":"3.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.10","versionStartIncluding":"3.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"3.19","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvlan: inherit needed_headroom and needed_tailroom from phy_dev\n\nipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),\nbut leave needed_headroom and needed_tailroom set to 0.\n\nWhen the underlying phy_dev (or stacked lower device) requires extra headroom\nor tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or\nveth with rx headroom), upper layers calculating packet headroom and tailroom\nfail to reserve sufficient space.\n\nThis can result in reallocation overhead, skb headroom underflows, or KASAN\nslab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header()\nprepends header data or when lower devices append tailroom.\n\nFix this by:\n1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init().\n2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans\n   in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events."}],"metrics":[{"cvssV3_1":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - On hosts where admins deployed ipvlan over phy_dev with non-zero headroom (WireGuard/IPsec/macsec/tunnels/veth-XDP), remote packets that trigger egress through the ipvlan netdev (TCP/UDP/ICMP responses, forwarded traffic) reach ipvlan_hard_header/dev_hard_header without local syscalls.\nAC:L - Once the stacked netdev exists, the attacker controls packet sizes and connection patterns to deterministically undersize skb headroom/tailroom; syzbot reproduced KASAN slab-UAF without races or uncontrollable memory layout.\nPR:N - Remote exploitation on pre-deployed ipvlan-over-encrypted/tunneled container or VPN hosts requires no credentials—only network reachability to services using that netdev; CAP_NET_ADMIN is only needed for the alternate local user-namespace setup path.\nUI:N - No victim interaction is required; the attacker either sends crafted network traffic to trigger kernel TX through ipvlan or self-configures the netdev stack via rtnetlink inside a user namespace.\nS:U - Impact is kernel slab skb/net_device memory corruption and local privilege escalation within the same kernel security authority, not a VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - Insufficient LL_RESERVED_SPACE causes pskb_expand_head to free still-referenced skb data and dev_hard_header skb_push to access memory outside the buffer; the fix cites KASAN slab-use-after-free, enabling arbitrary kernel memory disclosure.\nI:H - Slab UAF and skb headroom underflow during header prepend give heap-grooming and controlled overwrite primitives on attacker-influenced TX paths, suitable for kernel control-flow hijacking and code execution.\nA:H - Undersized headroom triggers skb_under_panic BUG and KASAN-reported slab-use-after-free oops/panic from softirq/TX paths; remote or local attackers can retrigger repeatedly for reliable kernel denial of service."}]}],"providerMetadata":{"dateUpdated":"2026-08-27T05:01:05.284Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/af602c4d0ee548da18e2409b4b4da1079625a372"},{"url":"https://git.kernel.org/stable/c/f3c17ff65f54781cde696e16a6c577615ed735aa"},{"url":"https://git.kernel.org/stable/c/c0fbe31f6b20ade0465130685859faa5c86fda59"},{"url":"https://git.kernel.org/stable/c/5f33188457bbcc1b11ca87084037963c516ed3d9"},{"url":"https://git.kernel.org/stable/c/5c2ca77212eb38559b0353b8363b7a84f4b019dd"},{"url":"https://git.kernel.org/stable/c/e16e960d55a40d36bd7c2494cc005e757dc9a1ef"}],"title":"ipvlan: inherit needed_headroom and needed_tailroom from phy_dev","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-74744","datePublished":"2026-08-26T14:36:54.773Z","dateReserved":"2026-08-15T05:44:03.931Z","dateUpdated":"2026-08-27T05:01:05.284Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-26 15:16:53","lastModifiedDate":"2026-08-27 06:17:24","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74744","Ordinal":"1","Title":"ipvlan: inherit needed_headroom and needed_tailroom from phy_dev","CVE":"CVE-2026-74744","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74744","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvlan: inherit needed_headroom and needed_tailroom from phy_dev\n\nipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),\nbut leave needed_headroom and needed_tailroom set to 0.\n\nWhen the underlying phy_dev (or stacked lower device) requires extra headroom\nor tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or\nveth with rx headroom), upper layers calculating packet headroom and tailroom\nfail to reserve sufficient space.\n\nThis can result in reallocation overhead, skb headroom underflows, or KASAN\nslab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header()\nprepends header data or when lower devices append tailroom.\n\nFix this by:\n1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init().\n2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans\n   in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.","Type":"Description","Title":"ipvlan: inherit needed_headroom and needed_tailroom from phy_dev"}]}}}