PT-2026-72932 · Linux+2 · Linux Kernel+2

CVE-2026-74480

·

Published

2026-08-15

·

Updated

2026-09-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to July 2026 Red Hat Enterprise Linux 10.2
Description A use-after-free issue exists in the net bridge component of the Linux kernel. The problem occurs in the br multicast leave group() function during the fast-leave path. When br multicast del pg() removes a port group, the loop continues to advance through the deleted entry using a stale pointer. This is particularly relevant when multicast-to-unicast is disabled, as br port group equal() matches entries by port only, potentially leaving the mp->ports pointer referencing a deleted port group. This flaw can be exploited to achieve privilege escalation.
Recommendations Update the Linux kernel to the version released in July 2026 or later. Update Red Hat Enterprise Linux 10.2 to a patched version.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:64770
ALSA-2026:66000
ALSA-2026:66180
AZL-96423
CVE-2026-74480
RHSA-2026:61973
RHSA-2026:62345
RHSA-2026:62372

Affected Products

Linux Kernel
Red Hat Enterprise Linux 10.2
Rocky Linux