CVE-2026-74492

Published: Ago 15, 2026 Last Modified: Ago 15, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: do not update comments from kernel-side hash adds

mtype_resize() copies comment pointers with memcpy(), not the comment
objects themselves. During the window after an entry has been copied but
before the table swap and backlog replay, the old table is still
published for packet-side updates while the replacement-table entry
already holds the same ip_set_comment_rcu pointer.

If xt_SET --add-set ... --exist hits that old entry in this window,
mtype_add() calls ip_set_init_comment() even though packet-side adds
carry no comment payload. That call frees the shared comment through the
old entry, so the replacement-table entry now holds a stale pointer.
When the queued add is replayed on the new table, mtype_add() calls
ip_set_init_comment() again and strlen() dereferences the stale pointer.

Fix this in mtype_add() by skipping ip_set_init_comment() when
ext->target marks a packet-side add. Userspace adds still update
comments, while packet-side adds can no longer free comment storage
shared with a resize copy.

https://git.kernel.org/stable/c/4ae701848e4ba9e9713375fb7d82218cbd309da2
https://git.kernel.org/stable/c/661ff9c0cfbe07f8eed920dde9f7781491738207
https://git.kernel.org/stable/c/77dbb248a5cc7a5270cd37bbb0b635bf059a872a
https://git.kernel.org/stable/c/c710e9bf38e4e71a8db85d26a0f70c0674664207
https://git.kernel.org/stable/c/f30415929be8aeb002d557c8d3f7ab2d2188003a