Linux Kernel Netfilter Vulnerability in Rate Matching Functionality
CVE-2026-74564

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-74564?

A vulnerability has been identified in the Linux kernel's netfilter module, specifically concerning the XT_HASHLIMIT_RATE_MATCH flag. This flag alters the behavior of the dsthash_ent structure, affecting hashtable entries. When improperly validated, there is a risk of uninitialized access to the burst field within the union, which may lead to unintended behavior. To mitigate this risk, it is essential to ensure that the XT_HASHLIMIT_RATE_MATCH mode flag is only used when requested by two or more rules associated with the same hashtable. Additionally, support for this flag should be rejected if it refers to kernel revisions prior to revision 3.

Affected Version(s)

Linux bea74641e3786d51dcf1175527cc1781420961c9 < 24683fea1f06bd3bd2707b99460e859bc6464c22

Linux bea74641e3786d51dcf1175527cc1781420961c9 < 32ec8d4aba2cf22e12bdc28df8c4bd833c195fc0

Linux bea74641e3786d51dcf1175527cc1781420961c9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.