Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-74739

CVE-2026-74739: Linux Kernel Buffer Overflow Vulnerability

CVE-2026-74739 is a buffer overflow flaw in the Linux kernel net/sched subsystem that causes slab-out-of-bounds memory access. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-74739 Overview

CVE-2026-74739 is a Linux kernel vulnerability in the net/sched subsystem, specifically within the cls_u32 traffic classifier. The flaw resides in u32_bind_class(), which unconditionally casts a filter handle to a tc_u_knode structure without checking whether the walker actually passed a tc_u_hnode (hash table node). This type confusion leads to a slab-out-of-bounds read of res->classid inside tc_cls_bind_class(). A local user with CAP_NET_ADMIN in a network namespace can trigger the condition using standard tc commands, causing kernel memory disclosure or instability.

Critical Impact

Local users able to configure traffic control can trigger a slab-out-of-bounds read in the kernel, risking information disclosure and kernel crashes.

Affected Products

  • Linux kernel net/sched subsystem — cls_u32 classifier
  • Linux stable branches prior to the fix commits (see references)
  • Distributions shipping affected upstream kernels

Discovery Timeline

  • 2026-08-26 - CVE-2026-74739 published to NVD
  • 2026-08-27 - Last updated in NVD database

Technical Details for CVE-2026-74739

Vulnerability Analysis

The cls_u32 classifier maintains two distinct object types: tc_u_hnode, representing filter hash tables, and tc_u_knode, representing individual filter key nodes. The walker function u32_walk() enumerates both types and passes each object as a generic filter handle (fh) to the walker callback.

When u32_bind_class() is invoked through this path, it unconditionally casts fh to struct tc_u_knode * and dereferences the res member. If fh actually points to a tc_u_hnode, that structure has no tcf_result field, so the read of res->classid in tc_cls_bind_class() falls outside the allocated slab object. The result is a type-confusion-driven out-of-bounds read [CWE-125].

Root Cause

The root cause is missing type discrimination in u32_bind_class(). The cls_u32 handle encoding distinguishes hash tables from key nodes via the TC_U32_KEY(handle) macro, but this check was absent before iterating on the object. Any hash table node reaching this path is treated as if it contained a tcf_result, producing the out-of-bounds access.

Attack Vector

Exploitation requires local access with the ability to configure Linux traffic control, typically CAP_NET_ADMIN in a user or network namespace. The provided reproducer chains four tc commands: attaching an hfsc qdisc to the loopback interface, creating an hfsc class, adding a u32 filter bound to that class, and then creating a second class. The final class creation triggers the class binding walk that reaches the vulnerable cast. The upstream fix adds a TC_U32_KEY(handle) check in u32_bind_class() to skip hash table nodes before the cast.

See the upstream fix commits for the exact patch details: Kernel Git Commit 19d114b, Kernel Git Commit 31f26a9, Kernel Git Commit 594a064, Kernel Git Commit 6d3724e, Kernel Git Commit e71f8e9, and Kernel Git Commit ec5f300.

Detection Methods for CVE-2026-74739

Indicators of Compromise

  • KASAN reports referencing slab-out-of-bounds reads in tc_cls_bind_class or u32_bind_class in kern.log or dmesg output.
  • Unexpected kernel oops or soft lockup entries following tc filter or tc class configuration changes.
  • Audit records showing unprivileged processes issuing tc commands via netlink RTM_NEWTFILTER or RTM_NEWTCLASS.

Detection Strategies

  • Monitor kernel logs for KASAN, UBSAN, or general protection fault entries originating in net/sched/cls_u32.c.
  • Track process execution of /sbin/tc and direct netlink socket usage by non-root or containerized workloads.
  • Correlate namespace creation events with subsequent traffic control modifications to identify anomalous privilege usage.

Monitoring Recommendations

  • Enable auditd rules covering the setsockopt and sendmsg syscalls on AF_NETLINK sockets with the NETLINK_ROUTE family.
  • Ship kernel ring buffer messages to a centralized log store and alert on classifier-related fault signatures.
  • Baseline expected tc usage across production hosts and flag deviations from container or orchestration workloads.

How to Mitigate CVE-2026-74739

Immediate Actions Required

  • Apply the upstream stable kernel updates that include the TC_U32_KEY(handle) check in u32_bind_class().
  • Restrict CAP_NET_ADMIN inside user namespaces and containers unless explicitly required for workload operation.
  • Inventory hosts running affected kernels and prioritize patching multi-tenant systems and container hosts.

Patch Information

The fix skips hash tables in u32_bind_class() via the TC_U32_KEY(handle) check, preventing the invalid cast. Backports are available across stable branches in the following commits: 19d114b, 31f26a9, 594a064, 6d3724e, e71f8e9, and ec5f300. Consult your Linux distribution vendor for the corresponding kernel package version.

Workarounds

  • Disable or blacklist the cls_u32 module where traffic control classification with u32 filters is not required.
  • Prevent unprivileged user namespaces from acquiring CAP_NET_ADMIN by setting kernel.unprivileged_userns_clone=0 where supported.
  • Enforce seccomp or Landlock policies that block tc-related netlink operations in untrusted workloads.
bash
# Configuration example: block loading of the vulnerable classifier module
echo 'install cls_u32 /bin/true' | sudo tee /etc/modprobe.d/disable-cls_u32.conf
sudo sysctl -w kernel.unprivileged_userns_clone=0

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.