ReviewHigh

CVE-2026-74736

Linux

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_bpf: reject dev-bound programs bound to a different device cls_bpf_prog_from_efd() obtained a SCHED_CLS program via bpf_prog_get_type_dev() but never verified that a device-bound (offloaded) program's bound netdev matches the TC netdev the classifier is being attached to. This let a program loaded with prog_ifindex for device A be attached via cls_bpf + skip_sw to device B; deleting device A then destroyed the program's offload state while it was still attached to device B, triggering a netdevsim WARN (panic...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.08.27
PRIORITY ASSESSMENT

Review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_bpf: reject dev-bound programs bound to a different device cls_bpf_prog_from_efd() obtained a SCHED_CLS program via bpf_prog_get_type_dev() but never verified that a device-bound (offloaded) program's bound netdev matches the TC netdev the classifier is being attached to. This let a program loaded with prog_ifindex for device A be attached via cls_bpf + skip_sw to device B; deleting device A then destroyed the program's offload state while it was still attached to device B, triggering a netdevsim WARN (panic...

Affected product and versions

Product
Linux
Affected versions
>= 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 < ec5a552f4b2d841c6c021752450716e1a9676661, >= 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 < daf546ab5763ce6a18280cb4db060e836c515301, >= 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 < adb3e7c26a51a10d94a241c6de7a81a2863dcacf, >= 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 < 5685bbbd3cbfbeb0de96a1d275a5ca073dfebb5e, >= 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 < 120977e2c096deea4e866e4273be9220b957c29e, >= 6.3
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available