Linux Kernel Zero-Copy Metadata Processing Vulnerability Affecting Network Drivers
CVE-2026-74707

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-74707?

In the Linux kernel, a vulnerability related to the validation of TX metadata within the zero-copy path has been identified. During the processing of network requests, the system allows user space to modify metadata after initial validation, potentially resulting in unauthorized access and control over network operations. A fix ensures that metadata is validated consistently during the entire transaction process, preventing manipulations that could compromise network security.

Affected Version(s)

Linux ca4419f15abd19ba8be1e109661b60f9f5b6c9f0 < 5fd121971912dee2f5af1efec64462ac722deb17

Linux ca4419f15abd19ba8be1e109661b60f9f5b6c9f0 < 0cc7aa6e0d19027fdd42e6fbd156267ac1e3bbba

Linux ca4419f15abd19ba8be1e109661b60f9f5b6c9f0 < 849b1664dbda1cf6c63e0fd4f9dec23782b8c851

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.