CVE-2026-74286

Published: Ago 15, 2026 Last Modified: Ago 15, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

net: pfcp: allocate per-cpu tstats for PFCP netdevs

PFCP uses dev_get_tstats64() as its ndo_get_stats64 callback, but
pfcp_link_setup() does not request NETDEV_PCPU_STAT_TSTATS. The net
core therefore leaves dev->tstats NULL for PFCP devices.

Creating a PFCP rtnetlink device can immediately ask the new netdev for
stats while building the RTM_NEWLINK notification. That reaches
dev_get_tstats64() and dereferences the NULL dev->tstats pointer.

Set pcpu_stat_type to NETDEV_PCPU_STAT_TSTATS during PFCP link setup so
the net core allocates the storage expected by dev_get_tstats64().

https://git.kernel.org/stable/c/24041543da8cd84eb5d8ae738c534372fff54820
https://git.kernel.org/stable/c/51a1d9836acc76a1bd16170b2f4b35f11036593f
https://git.kernel.org/stable/c/56b4ad500fd1282ef04db3c4beae5b54ab093a53
https://git.kernel.org/stable/c/67e4b283de36d9eebf95acdea5d6674b6ef4b2f4