CVE-2026-74739: Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: skip hash tables in u32_bind_class() u32_walk() enumerates both struct tc_u_hnode and struct tc_u_knode through the walker callback. u32_bind_class() unconditionally casts the passed fh to tc_u_knode and accesses &n->res, so when fh is actually a tc_u_hnode, which has no tcf_result member, this results in a slab-out-of-bounds read of res->classid in tc_cls_bind_class(). The issue can be reproduced with the following commands: tc qdisc add dev lo root handle 1: hfsc tc class add dev lo parent 1: classid 1:1 hfsc sc rate 1000kbit tc filter add dev lo parent 1:1 protocol ip prio 1 u32 match u32 0 0 flowid 1:1 tc class add dev lo parent 1: classid 1:2 hfsc sc rate 2000kbit Fix this by skipping hash tables via the TC_U32_KEY(handle) check.

Affected products

  • Linux Linux: from 4.14, before 6.1.184 (fixed in 6.1.184); from 6.2, before 6.6.153 (fixed in 6.6.153); from 6.7, before 6.12.105 (fixed in 6.12.105); from 6.13, before 6.18.46 (fixed in 6.18.46); from 6.19, before 7.1.10 (fixed in 7.1.10)

Published 2026-08-26. Last modified 2026-08-27.