CVE-2026-74479

HIGHPre-NVD 7.87.8
EchelonGraph scoreHIGH confidence

Score 7.8 from GitHub Security Advisory (severity: HIGH) published 2026-08-15. a secondary CVSS source baseline 7.8; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, secondary
Trending — 5 sources updated this week
7.8EG
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS: 7.8Exploit: None knownExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

In the Linux kernel, the following vulnerability has been resolved:

net: pktgen: fix proc entry use-after-free

pktgen_change_name() replaces pkt_dev->entry while holding t->if_lock. pktgen_remove_device() removes the same entry before _rem_dev_from_if_list() takes that lock.

This allows the following interleaving:

CPU 0 (NETDEV_CHANGENAME) CPU 1 (kpktgend) if_lock(t) proc_remove(pkt_dev->entry) proc_remove(pkt_dev->entry) pkt_dev->entry = proc_create_data(...) if_unlock(t)

The kthread can pass the stale proc_dir_entry to proc_remove() after the rename path has freed it. A reproducer with a widened race window reports:

BUG: KASAN: slab-use-after-free in proc_remove+0x78/0x80 Read of size 8 at addr ffff8881478fea70 by task kpktgend_0/67 Call Trace: proc_remove+0x78/0x80 pktgen_remove_device.isra.0+0x11c/0x4c0 pktgen_thread_worker+0x1214/0x6bc0 kthread+0x2c6/0x3b0 Allocated by task 95: __proc_create+0x204/0x790 proc_create_data+0x72/0xe0 pktgen_thread_write+0xd61/0x1510 Freed by task 28: kmem_cache_free+0xcb/0x3d0 proc_free_inode+0x5b/0x80 rcu_core+0x50a/0x1850 The buggy address belongs to the object at ffff8881478fea00 which belongs to the cache proc_dir_entry of size 192

Move proc_remove() into the if_lock-protected list removal helper. Keep it before list_del_rcu() to preserve the ordering required by add_device(). The rename path must then finish replacing the entry before removal, or it observes that the device is no longer on the list.

CVSS v3
7.8
EG Score
7.8(high)
EG Risk
40(Track)
EG Risk 40/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity78% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
0%
EPSS %ILE
3%
KEV
Not listed

Published

August 15, 2026

Last Modified

August 17, 2026

Advisory Details (3)

Auto-updated Aug 17, 2026
No patch confirmed yet.
generic

net: pktgen: fix proc entry use-after-free - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/b006a5404470bd3eb2aa0425fc447183032047ef
generic

net: pktgen: fix proc entry use-after-free - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/817ff6efdb7f484ea547218e11e17d8e43daa3b4
generic

net: pktgen: fix proc entry use-after-free - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/4ef801b838d85c0ea5852c50667f7344ce3b6cd0

Vendor Advisories for CVE-2026-74479(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Data Freshness Timeline

(refreshed 23× in last 7d / 23× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-08-20 13:05 UTCGHSA enrichment
  2. 2026-08-19 23:46 UTCEG score recompute
  3. 2026-08-19 23:46 UTCGHSA enrichment
  4. 2026-08-19 17:04 UTCEPSS rescore
  5. 2026-08-19 10:42 UTCGHSA enrichment
  6. 2026-08-18 21:38 UTCGHSA enrichment
  7. 2026-08-18 08:35 UTCGHSA enrichment
  8. 2026-08-17 19:29 UTCEG score recompute
  9. 2026-08-17 19:29 UTCGHSA enrichment
  10. 2026-08-17 13:47 UTCEPSS rescore
  11. 2026-08-17 06:24 UTCEG score recompute
  12. 2026-08-17 06:24 UTCGHSA enrichment
  13. 2026-08-17 05:55 UTCEG score recompute 7.80
  14. 2026-08-17 05:55 UTCGHSA enrichment
  15. 2026-08-17 05:54 UTCMITRE cvelistV5CVSS v3 → 7.8 · severity → HIGH
  16. 2026-08-17 05:25 UTCEG score recompute
  17. 2026-08-17 05:25 UTCGHSA enrichment
  18. 2026-08-17 05:24 UTCMITRE cvelistV5
  19. 2026-08-16 14:56 UTCEPSS rescore
  20. 2026-08-16 14:56 UTCEPSS rescore
  21. 2026-08-15 13:27 UTCNVD update
  22. 2026-08-15 12:40 UTCEG score recompute
  23. 2026-08-15 12:37 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-74479?
CVE-2026-74479 is a high vulnerability published on August 15, 2026. In the Linux kernel, the following vulnerability has been resolved: net: pktgen: fix proc entry use-after-free pktgenchangename() replaces pktdev->entry while holding t->iflock. pktgenremovedevice() removes the same entry before remdevfromif_list() takes that lock. This allows the following…
When was CVE-2026-74479 disclosed?
CVE-2026-74479 was first published in the National Vulnerability Database on August 15, 2026, with the most recent update on August 17, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-74479 actively exploited?
CVE-2026-74479 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 97.5% of all scored CVEs.
What is the CVSS score of CVE-2026-74479?
CVE-2026-74479 has a CVSS v3 base score of 7.8 (NVD).
How do I remediate CVE-2026-74479?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-74479, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-74479

Explore →

Is Your Infrastructure Affected by CVE-2026-74479?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.