Linux Kernel Zero-Copy Metadata Processing Vulnerability Affecting Network Drivers
CVE-2026-74707
Currently unrated
What is CVE-2026-74707?
In the Linux kernel, a vulnerability related to the validation of TX metadata within the zero-copy path has been identified. During the processing of network requests, the system allows user space to modify metadata after initial validation, potentially resulting in unauthorized access and control over network operations. A fix ensures that metadata is validated consistently during the entire transaction process, preventing manipulations that could compromise network security.
Affected Version(s)
Linux ca4419f15abd19ba8be1e109661b60f9f5b6c9f0 < 5fd121971912dee2f5af1efec64462ac722deb17
Linux ca4419f15abd19ba8be1e109661b60f9f5b6c9f0 < 0cc7aa6e0d19027fdd42e6fbd156267ac1e3bbba
Linux ca4419f15abd19ba8be1e109661b60f9f5b6c9f0 < 849b1664dbda1cf6c63e0fd4f9dec23782b8c851