Use After Free Vulnerability in Linux Kernel's RXRPC Component
CVE-2026-74433
What is CVE-2026-74433?
A Use After Free vulnerability has been identified in the RXRPC component of the Linux kernel, specifically within the rxgk_issue_challenge() function. This issue arises when the function does not properly manage memory allocation, leading to the potential for accessing freed memory. The vulnerability can be exploited by manipulating the challenge content while ensuring that the reference passed to the tracepoint points to a memory page that has already been freed. This oversight necessitates an immediate resolution to enhance the security posture of the kernel and prevent possible exploitation.
Affected Version(s)
Linux 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a < 844b8525ce503405c462ad67f750bec648720397
Linux 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a < 83bb0ed050e2ad9453d8ef50e4d6e624eac6eed8
Linux 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a < 107a4cb0d47e735830f852d83970d5c81f8e1e08