CVE-2026-74656

HIGHPre-NVD 7.87.8
EchelonGraph scoreHIGH confidence

Score 7.8 from GitHub Security Advisory (severity: HIGH) published 2026-08-22. a secondary CVSS source baseline 7.8; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, secondary
Trending — 4 sources updated this week
7.8EG
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS: 7.8Exploit: None knownExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

In the Linux kernel, the following vulnerability has been resolved:

ipv4: fix use-after-free in fib_nhc_update_mtu()

fib_nhc_update_mtu() walks the nexthop exception table under RTNL, but RTNL does not serialize this walk with PMTU exception updates. The walk uses rcu_dereference_protected() with a constant true condition without holding fnhe_lock.

The following interleaving can therefore occur:

CPU 0 CPU 1 fib_nhc_update_mtu() update_or_create_fnhe() load fnhe spin_lock_bh(&fnhe_lock) fnhe_remove_oldest() unlink fnhe kfree_rcu(fnhe, rcu) access fnhe after grace period

KASAN reported:

BUG: KASAN: slab-use-after-free in fib_nhc_update_mtu+0x3df/0x410 Read of size 8 at addr ffff888107d49000 by task poc/90 Call Trace: fib_nhc_update_mtu+0x3df/0x410 fib_sync_mtu+0x7a/0xd0 fib_netdev_event+0x229/0x3f0 netif_set_mtu_ext+0x33a/0x570 dev_set_mtu+0x88/0x120

The same walk updates fnhe_pmtu and fnhe_mtu_locked. These fields form a pair and other writers serialize them with fnhe_lock. RCU alone prevents reclamation, but would still allow concurrent writers to leave a mixed pair.

Walk the table under RCU and acquire fnhe_lock only while updating each exception. RCU keeps the current entry alive while the short critical section serializes its paired PMTU fields. This avoids holding the global lock while scanning all 2048 buckets for every nexthop.

CVSS v3
7.8
EG Score
7.8(high)
EG Risk
40(Track)
EG Risk 40/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity78% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
0%
EPSS %ILE
3%
KEV
Not listed

Published

August 22, 2026

Last Modified

August 25, 2026

Advisory Details (8)

Auto-updated Aug 25, 2026
No patch confirmed yet.
generic

ipv4: fix use-after-free in fib_nhc_update_mtu() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/bc5bde9ce3cc36502839dfe98e068f7303a50982
generic

ipv4: fix use-after-free in fib_nhc_update_mtu() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/ed503eaad62f20cdd5122d7c3078a648a99c8f16
generic

ipv4: fix use-after-free in fib_nhc_update_mtu() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/63996ffc594d128ccec8fc0983f91effd2d3adc4
generic

ipv4: fix use-after-free in fib_nhc_update_mtu() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/5a28a4b22dde92f9d293b94236314b8d6181dc4a
generic

ipv4: fix use-after-free in fib_nhc_update_mtu() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/dfe388da13aa784851e5ebbea90afbb099075761
generic

ipv4: fix use-after-free in fib_nhc_update_mtu() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/e00f7d2b5f2540a3415a229c982af7a25ff6362e
generic

ipv4: fix use-after-free in fib_nhc_update_mtu() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/e1e602d6b22d5cb1641c4459c487eb18bf569e0a
generic

ipv4: fix use-after-free in fib_nhc_update_mtu() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/fd39e711866498ae94fcf9acf6f422a4f045b681

Vendor Advisories for CVE-2026-74656(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Data Freshness Timeline

(refreshed 25× in last 7d / 28× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-08-30 01:37 UTCEG score recompute
  2. 2026-08-30 01:37 UTCGHSA enrichment
  3. 2026-08-30 01:22 UTCEPSS rescore
  4. 2026-08-29 13:14 UTCGHSA enrichment
  5. 2026-08-29 00:50 UTCEG score recompute
  6. 2026-08-29 00:49 UTCGHSA enrichment
  7. 2026-08-28 21:42 UTCEPSS rescore
  8. 2026-08-28 09:01 UTCGHSA enrichment
  9. 2026-08-27 20:34 UTCEG score recompute
  10. 2026-08-27 20:34 UTCGHSA enrichment
  11. 2026-08-27 14:25 UTCEPSS rescore
  12. 2026-08-27 08:03 UTCGHSA enrichment
  13. 2026-08-26 19:39 UTCEG score recompute
  14. 2026-08-26 19:39 UTCGHSA enrichment
  15. 2026-08-26 14:47 UTCEPSS rescore
  16. 2026-08-26 07:16 UTCGHSA enrichment
  17. 2026-08-25 18:53 UTCEG score recompute
  18. 2026-08-25 18:53 UTCGHSA enrichment
  19. 2026-08-25 13:49 UTCEPSS rescore
  20. 2026-08-25 06:29 UTCEG score recompute
  21. 2026-08-25 06:29 UTCGHSA enrichment
  22. 2026-08-25 05:56 UTCEG score recompute 7.80
  23. 2026-08-25 05:56 UTCGHSA enrichment
  24. 2026-08-25 05:55 UTCMITRE cvelistV5CVSS v3 → 7.8 · severity → HIGH
  25. 2026-08-24 14:18 UTCEPSS rescore
Show 3 more
  1. 2026-08-22 16:24 UTCNVD update
  2. 2026-08-22 15:41 UTCEG score recompute
  3. 2026-08-22 15:35 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-74656?
CVE-2026-74656 is a high vulnerability published on August 22, 2026. In the Linux kernel, the following vulnerability has been resolved: ipv4: fix use-after-free in fibnhcupdate_mtu() fibnhcupdate_mtu() walks the nexthop exception table under RTNL, but RTNL does not serialize this walk with PMTU exception updates. The walk uses rcudereferenceprotected() with a…
When was CVE-2026-74656 disclosed?
CVE-2026-74656 was first published in the National Vulnerability Database on August 22, 2026, with the most recent update on August 25, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-74656 actively exploited?
CVE-2026-74656 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 97.5% of all scored CVEs.
What is the CVSS score of CVE-2026-74656?
CVE-2026-74656 has a CVSS v3 base score of 7.8 (NVD).
How do I remediate CVE-2026-74656?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-74656, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-74656

Explore →

Is Your Infrastructure Affected by CVE-2026-74656?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.