CVE EVIDENCE REVIEW
ReviewCriticalEvidence review

CVE-2026-74746 evidence review

Linux

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() only treats original-direction tuple nodes as owning entries. Publishing the original node first lets GC observe and free a flow while flow_offload_add() is still inserting the reply node. Publish the reply node first and the original node last so GC never sees a partially installed flow. KASAN can trigger slab-use-after-free read and write reports in the flowtable/rhashtable path (rht_deferred_worker, jhash, flow_offload_del, flow_offload_lookup, e...

Open CVE record
Evidence review

This record remains available for product and version identification, but it is not presented as a complete remediation procedure. Confirm the affected range and the supported fix in a direct vendor advisory before changing production systems.

ProductLinux
Affected versions>= ac2a66665e231847cab11b8c8e844ce43207dd2e < 0a00254585827f1695aa2700114af622ea754cfa, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < be345dcbddb4643a54252b954af974b16eda8f91, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < 211ee5d998d92a7d548811939c65942d06c146e4, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < d37917e7bebe078f3c17e47fd6fc1c9f6e8497b2, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < 972fdf7c4f5c282a239c88fea614b056c33dc025, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < d9d3050a70efe217e73a0751e55fdae6a7092620, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < d16b71231e65cb05daea2b45701fcf09cef041e7, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < 2014ac62df9d45bb9a004a043e85df7be09ed780, >= 4.16
Fixed versionsNo verified fixed-version field is available yet
Priority basisReview · CVSS 9.8 · EPSS -
01

Identify the product and installed version

Record whether Linux is present, where it is installed, and which interfaces are exposed.

  • Record the product name, package or appliance identifier, and installed version.
  • Identify internet-facing, administrative, API, and internal access paths.
  • Preserve the pre-change configuration and relevant service logs.
02

Compare the affected range

Use the current record as an identification aid: >= ac2a66665e231847cab11b8c8e844ce43207dd2e < 0a00254585827f1695aa2700114af622ea754cfa, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < be345dcbddb4643a54252b954af974b16eda8f91, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < 211ee5d998d92a7d548811939c65942d06c146e4, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < d37917e7bebe078f3c17e47fd6fc1c9f6e8497b2, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < 972fdf7c4f5c282a239c88fea614b056c33dc025, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < d9d3050a70efe217e73a0751e55fdae6a7092620, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < d16b71231e65cb05daea2b45701fcf09cef041e7, >= ac2a66665e231847cab11b8c8e844ce43207dd2e < 2014ac62df9d45bb9a004a043e85df7be09ed780, >= 4.16. Resolve incomplete inventory results before deciding that an asset is unaffected.

03

Verify the authoritative remediation source

Open the linked source material and locate a direct vendor advisory for this CVE. Confirm the supported fixed release and product-specific update path before making a production change.

Operational boundary

This page does not replace the vendor advisory, support contract, change-management process, or recovery plan. Do not infer that an asset is unaffected from an incomplete inventory query or a missing fixed-version field.