PT-2026-72932 · Linux+2 · Linux Kernel+2
CVE-2026-74480
·
Published
2026-08-15
·
Updated
2026-09-12
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to July 2026
Red Hat Enterprise Linux 10.2
Description
A use-after-free issue exists in the net bridge component of the Linux kernel. The problem occurs in the
br multicast leave group() function during the fast-leave path. When br multicast del pg() removes a port group, the loop continues to advance through the deleted entry using a stale pointer. This is particularly relevant when multicast-to-unicast is disabled, as br port group equal() matches entries by port only, potentially leaving the mp->ports pointer referencing a deleted port group. This flaw can be exploited to achieve privilege escalation.Recommendations
Update the Linux kernel to the version released in July 2026 or later.
Update Red Hat Enterprise Linux 10.2 to a patched version.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat Enterprise Linux 10.2
Rocky Linux